Vulnerability CVE-2011-0724


Published: 2011-02-18   Modified: 2012-02-13

Description:
The Live DVD for Edubuntu 9.10, 10.04 LTS, and 10.10 does not correctly regenerate iTALC private keys after installation, which causes each installation to have the same fixed key, which allows remote attackers to gain privileges.

Type:

CWE-310

(Cryptographic Issues)

CVSS2 => (AV:N/AC:M/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
9.3/10
10/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
Ubuntu -> Live dvd 
Ubuntu -> Edubuntu 

 References:
http://xforce.iss.net/xforce/xfdb/65389
http://www.vupen.com/english/advisories/2011/0378
http://www.ubuntu.com/usn/USN-1061-1
http://www.securityfocus.com/bid/46346

Copyright 2024, cxsecurity.com

 

Back to Top