4.3
CVSSv2

CVE-2011-4407

Published: 14/05/2014 Updated: 14/05/2014
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

ppa.py in Software Properties prior to 0.81.13.3 does not validate the server certificate when downloading PPA GPG key fingerprints, which allows man-in-the-middle (MITM) malicious users to spoof GPG keys for a package repository.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

canonical ubuntu linux 11.04

canonical software-properties

canonical ubuntu linux 10.04

canonical ubuntu linux 10.10

canonical ubuntu linux 11.10

Vendor Advisories

Software Properties could be tricked into installing arbitrary PPA GPG keys ...