6.8
CVSSv2

CVE-2011-4408

Published: 16/06/2012 Updated: 29/08/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

The Single Sign On Client (ubuntu-sso-client) for Ubuntu 11.04 and 11.10 does not properly validate SSL certificates when using HTTPS, which allows remote malicious users to spoof a server and modify or read sensitive data via a man-in-the-middle (MITM) attack.

Vulnerable Product Search on Vulmon Subscribe to Product

canonical ubuntu linux 11.04

canonical ubuntu linux 11.10

Vendor Advisories

Fraudulent security certificates could allow sensitive information to be exposed when accessing the Internet ...