Index
Bugtraq
Pełna lista
Błędy
Sztuczki
Exploity
Dorks list
Tylko z CVE
Tylko z CWE
Bogus
Ranking
CVEMAP
Świeża lista CVE
Producenci
Produkty
Słownik CWE
Sprawdź nr. CVE
Sprawdź nr. CWE
Szukaj
W Bugtraq
W bazie CVE
Po autorze
Po nr. CVE
Po nr. CWE
Po producencie
Po produkcie
RSS
Bugtraq
CVEMAP
CVE Produkty
Tylko Błędy
Tylko Exploity
Tylko Dorks
Więcej
cIFrex
Facebook
Twitter
Donate
O bazie
Lang
Polish
English
Submit
Podatności dla
'Update-manager'
2014-04-27
CVE-2011-3152
CWE-310
DistUpgrade/DistUpgradeFetcherCore.py in Update Manager before 1:0.87.31.1, 1:0.134.x before 1:0.134.11.1, 1:0.142.x before 1:0.142.23.1, 1:0.150.x before 1:0.150.5.1, and 1:0.152.x before 1:0.152.25.5 on Ubuntu 8.04 through 11.10 does not verify the GPG signature before extracting an upgrade tarball, which allows man-in-the-middle attackers to (1) create or overwrite arbitrary files via a directory traversal attack using a crafted tar file, or (2) bypass authentication via a crafted meta-release file.
2014-04-17
CVE-2011-3154
CWE-59
DistUpgrade/DistUpgradeViewKDE.py in Update Manager before 1:0.87.31.1, 1:0.134.x before 1:0.134.11.1, 1:0.142.x before 1:0.142.23.1, 1:0.150.x before 1:0.150.5.1, and 1:0.152.x before 1:0.152.25.5 does not properly create temporary files, which allows local users to obtain the XAUTHORITY file content for a user via a symlink attack on the temporary file.
>>>
Vendor:
Canonical
40
Produkty
Ubuntu linux
Reportbug
Spread
Bazaar
Apparmor
Checkinstall
Ubuntu
Ubuntu enterprise cloud
Accountsservice
PHP5
Ubuntu software properties
Telepathy-idle
Software-properties
Apt-xapian-index
MAAS
Metal as a service
Libpam-modules
Update-manager
Ltsp display manager
Acpi-support
Lxcfs
Ubuntu core
Ubuntu touch
Ubuntu-core-launcher
LXD
Openstack ironic
JUJU
Ubuntu-image
Screen-resolution-extra
Ubuntu download manager
Snapd
Cloud-init
Ubuntu cobbler
Microk8s
C-kernel
Subiquity
Ubuntu-ui-toolkit
Remote-login-service
Courier-authlib
Multipass
Copyright
2024
, cxsecurity.com
Back to Top