Búsqueda de    
Vulnerabilidad   
    Buscar 219043 Descripciones CVE y
99761 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.71016
Categoría:Ubuntu Local Security Checks
Título:Ubuntu USN-1283-1 (apt)
Resumen:NOSUMMARY
Descripción:Description:
The remote host is missing an update to apt
announced via advisory USN-1283-1.

Details:

It was discovered that APT incorrectly handled the Verify-Host
configuration option. If a remote attacker were able to perform a
man-in-the-middle attack, this flaw could potentially be used to steal
repository credentials. This issue only affected Ubuntu 10.04 LTS and
10.10. (CVE-2011-3634)

USN-1215-1 fixed a vulnerability in APT by disabling the apt-key net-update
option. This update re-enables the option with corrected verification.
Original advisory details:
It was discovered that the apt-key utility incorrectly verified GPG
keys when downloaded via the net-update option. If a remote attacker were
able to perform a man-in-the-middle attack, this flaw could potentially be
used to install altered packages.

Solution:
The problem can be corrected by updating your system to the following
package versions:

Ubuntu 11.04:
apt 0.8.13.2ubuntu4.3

Ubuntu 10.10:
apt 0.8.3ubuntu7.3

Ubuntu 10.04 LTS:
apt 0.7.25.3ubuntu9.9

Ubuntu 8.04 LTS:
apt 0.7.9ubuntu17.4

http://www.securityspace.com/smysecure/catid.html?in=USN-1283-1

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2011-3634
http://www.ubuntu.com/usn/USN-1283-1
CopyrightCopyright (c) 2012 E-Soft Inc. http://www.securityspace.com

Esta es sólo una de 99761 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2024 E-Soft Inc. Todos los derechos reservados.