Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2011-3152
Description:DistUpgrade/DistUpgradeFetcherCore.py in Update Manager before 1:0.87.31.1, 1:0.134.x before 1:0.134.11.1, 1:0.142.x before 1:0.142.23.1, 1:0.150.x before 1:0.150.5.1, and 1:0.152.x before 1:0.152.25.5 on Ubuntu 8.04 through 11.10 does not verify the GPG signature before extracting an upgrade tarball, which allows man-in- the-middle attackers to (1) create or overwrite arbitrary files via a directory traversal attack using a crafted tar file, or (2) bypass authentication via a crafted meta-release file.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2011-3152
BugTraq ID: 50833
http://www.securityfocus.com/bid/50833
http://www.osvdb.org/77642
http://secunia.com/advisories/47024
http://www.ubuntu.com/usn/USN-1284-1
XForce ISS Database: ubuntu-update-gpg-sec-bypass(71494)
https://exchange.xforce.ibmcloud.com/vulnerabilities/71494




© 1998-2025 E-Soft Inc. All rights reserved.