CVE-2011-0724
Publication date 10 February 2011
Last updated 24 July 2024
Ubuntu priority
The Live DVD for Edubuntu 9.10, 10.04 LTS, and 10.10 does not correctly regenerate iTALC private keys after installation, which causes each installation to have the same fixed key, which allows remote attackers to gain privileges.
From the Ubuntu Security Team
Stéphane Graber discovered that the iTALC private keys shipped with the Edubuntu Live media were not correctly regenerated once Edubuntu was installed. If an iTALC client was installed with the vulnerable keys, a remote attacker could gain control of the system.
References
Related Ubuntu Security Notices (USN)
- USN-1061-1
- iTALC vulnerability
- 11 February 2011