Summary
Ubuntu Update for Linux kernel vulnerabilities USN-1265-1
Solution
Please Install the Updated Packages.
Insight
Marc Deslauriers discovered that system-config-printer's cupshelpers scripts used by the Ubuntu automatic printer driver download service queried the OpenPrinting database using an insecure connection. If a remote attacker were able to perform a man-in-the-middle attack, this flaw could be exploited to install altered packages and repositories.
Affected
system-config-printer on Ubuntu 11.04
Severity
Classification
-
CVE CVE-2011-4405 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities