CVE-2011-4407
Publication date 26 January 2012
Last updated 24 July 2024
Ubuntu priority
ppa.py in Software Properties before 0.81.13.3 does not validate the server certificate when downloading PPA GPG key fingerprints, which allows man-in-the-middle (MITM) attackers to spoof GPG keys for a package repository.
Status
Package | Ubuntu Release | Status |
---|---|---|
software-properties | ||
References
Related Ubuntu Security Notices (USN)
- USN-1352-1
- Software Properties vulnerability
- 31 January 2012