Your submission was sent successfully! Close

You have successfully unsubscribed! Close

CVE-2011-4407

Published: 26 January 2012

ppa.py in Software Properties before 0.81.13.3 does not validate the server certificate when downloading PPA GPG key fingerprints, which allows man-in-the-middle (MITM) attackers to spoof GPG keys for a package repository.

Priority

Medium

Status

Package Release Status
software-properties
Launchpad, Ubuntu, Debian
upstream Needs triage

hardy Ignored
(end of life)
lucid
Released (0.75.10.2)
maverick
Released (0.76.7.1)
natty
Released (0.80.9.1)
oneiric
Released (0.81.13.3)