Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 510
Alerts This Week
Warning Icon 1 510

Ubuntu 11.10: USN-1464-1 Moderate: sso-client Man-In-The-Middle Risk

ubuntu
Calendar Grey June 6, 2012
Scroller Ubuntu
Debian Security Alert DSA-1234-1 highlights a major vulnerability in the web server that may allow unauthorized access to sensitive information.
Fraudulent security certificates could allow sensitive information to be exposed when accessing the Internet.

Summary

Fraudulent security certificates could allow sensitive information to

be exposed when accessing the Internet.

Software Description:

- ubuntu-sso-client: Ubuntu Single Sign-On client

Details:

It was discovered that the Ubuntu Single Sign On Client incorrectly

validated server certificates when using HTTPS connections. If a remote

attacker were able to perform a man-in-the-middle attack, this flaw could

be exploited to alter or compromise confidential information.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 11.10:
  ubuntu-sso-client               1.4.1-0ubuntu1.1

Ubuntu 11.04:
  ubuntu-sso-client               1.2.1-0ubuntu2.1

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1464-1

CVE-2011-4408

June 06, 2012

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.