CVE-2011-3367

Publication date 29 November 2011

Last updated 24 July 2024


Ubuntu priority

Negligible

Why this priority?

Description

Arora, possibly 0.11 and other versions, does not use a certain font when rendering certificate fields in a security dialog, which allows remote attackers to spoof the common name (CN) of a certificate via rich text.

Read the notes from the security team

Status

Package Ubuntu Release Status
arora 11.10 oneiric Ignored
11.04 natty Ignored
10.10 maverick Ignored
10.04 LTS lucid Ignored
8.04 LTS hardy Not in release

Notes


jdstrand

no updates for this issue as of 2011-10-14 while there are non-escaped strings, they are only used when QT is compiled without SSL support, and all versions of Ubuntu compile QT with SSL support.