Vulnerability Name: | CVE-2011-3152 (CCN-71494) | ||||||||||||
Assigned: | 2011-11-28 | ||||||||||||
Published: | 2011-11-28 | ||||||||||||
Updated: | 2017-08-29 | ||||||||||||
Summary: | DistUpgrade/DistUpgradeFetcherCore.py in Update Manager before 1:0.87.31.1, 1:0.134.x before 1:0.134.11.1, 1:0.142.x before 1:0.142.23.1, 1:0.150.x before 1:0.150.5.1, and 1:0.152.x before 1:0.152.25.5 on Ubuntu 8.04 through 11.10 does not verify the GPG signature before extracting an upgrade tarball, which allows man-in-the-middle attackers to (1) create or overwrite arbitrary files via a directory traversal attack using a crafted tar file, or (2) bypass authentication via a crafted meta-release file. | ||||||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||||||
CVSS v2 Severity: | 6.4 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N) 5.2 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N/E:U/RL:W/RC:C)
4.0 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:W/RC:C)
| ||||||||||||
Vulnerability Type: | CWE-310 | ||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2011-3152 Source: CCN Type: SA47024 Ubuntu update for update-manager Source: SECUNIA Type: UNKNOWN 47024 Source: OSVDB Type: UNKNOWN 77642 Source: CCN Type: OSVDB ID: 77642 Update Manager Tar File Handling MitM Remote Arbitrary File Overwrite Source: BID Type: UNKNOWN 50833 Source: CCN Type: BID-50833 Ubuntu Update Manager GPG Signature Verification Security Bypass Vulnerability Source: UBUNTU Type: Vendor Advisory USN-1284-1 Source: CCN Type: USN-1284-1 Update Manager vulnerabilities Source: CONFIRM Type: UNKNOWN https://bugs.launchpad.net/ubuntu/%2Bsource/update-manager/%2Bbug/881548 Source: XF Type: UNKNOWN ubuntu-update-gpg-sec-bypass(71494) Source: XF Type: UNKNOWN ubuntu-update-gpg-sec-bypass(71494) | ||||||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||||||
Oval Definitions | |||||||||||||
| |||||||||||||
BACK |