7.5
CVSSv2

CVE-2011-4409

Published: 16/06/2012 Updated: 29/08/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The Ubuntu One Client for Ubuntu 10.04 LTS, 11.04, 11.10, and 12.04 LTS does not properly validate SSL certificates, which allows remote malicious users to spoof a server and modify or read sensitive information via a man-in-the-middle (MITM) attack.

Vulnerable Product Search on Vulmon Subscribe to Product

canonical ubuntu linux 10.04

canonical ubuntu linux 11.04

canonical ubuntu linux 11.10

canonical ubuntu linux 12.04

Vendor Advisories

Fraudulent security certificates could allow sensitive information to be exposed when accessing the Internet ...
Fraudulent security certificates could allow sensitive information to be exposed when accessing the Internet ...
Fraudulent security certificates could allow sensitive information to be exposed when accessing the Internet ...