Canonical Update Manager (update-manager) 1:0.87.24

CPE Details

Canonical Update Manager (update-manager) 1:0.87.24
1°dp°0.87.24
2014-04-17
13h22 +00:00
2014-04-24
17h31 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:canonical:update-manager:1\:0.87.24:*:*:*:*:*:*:*

Informations

Vendor

canonical

Product

update-manager

Version

1°dp°0.87.24

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2011-3152 2014-04-27 18h00 +00:00 DistUpgrade/DistUpgradeFetcherCore.py in Update Manager before 1:0.87.31.1, 1:0.134.x before 1:0.134.11.1, 1:0.142.x before 1:0.142.23.1, 1:0.150.x before 1:0.150.5.1, and 1:0.152.x before 1:0.152.25.5 on Ubuntu 8.04 through 11.10 does not verify the GPG signature before extracting an upgrade tarball, which allows man-in-the-middle attackers to (1) create or overwrite arbitrary files via a directory traversal attack using a crafted tar file, or (2) bypass authentication via a crafted meta-release file.
6.4
CVE-2011-3154 2014-04-17 12h00 +00:00 DistUpgrade/DistUpgradeViewKDE.py in Update Manager before 1:0.87.31.1, 1:0.134.x before 1:0.134.11.1, 1:0.142.x before 1:0.142.23.1, 1:0.150.x before 1:0.150.5.1, and 1:0.152.x before 1:0.152.25.5 does not properly create temporary files, which allows local users to obtain the XAUTHORITY file content for a user via a symlink attack on the temporary file.
1.9