← Back

CVE-2011-4407

nvd nist
Published: May 14, 2014Modified: May 6, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

ppa.py in Software Properties before 0.81.13.3 does not validate the server certificate when downloading PPA GPG key fingerprints, which allows man-in-the-middle (MITM) attackers to spoof GPG keys for a package repository.

Affected (5)

2 products
Software Properties
Ubuntu Linux
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Up to 0.81.13.1
Canonical
Version 10.04
Version 10.10
Version 11.04
Version 11.10

References (4)

Timeline

No history available yet.