The base-files package prior to 5.0.0ubuntu7.1 on Ubuntu 9.10 and prior to 5.0.0ubuntu20.10.04.2 on Ubuntu 10.04 LTS, as shipped on Dell Latitude 2110 netbooks, does not require authentication for package installation, which allows remote archive servers and man-in-the-middle malicious users to execute arbitrary code via a crafted package.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
ubuntu ubuntu_linux 10.04 |
||
ubuntu ubuntu_linux 9.10 |