CVE-2011-4408

Publication date 6 June 2012

Last updated 24 July 2024


Ubuntu priority

The Single Sign On Client (ubuntu-sso-client) for Ubuntu 11.04 and 11.10 does not properly validate SSL certificates when using HTTPS, which allows remote attackers to spoof a server and modify or read sensitive data via a man-in-the-middle (MITM) attack.

Read the notes from the security team

Status

Package Ubuntu Release Status
ubuntu-sso-client 12.04 LTS precise
Not affected
11.10 oneiric
Fixed 1.4.1-0ubuntu1.1
11.04 natty
Fixed 1.2.1-0ubuntu2.1
10.04 LTS lucid Not in release
8.04 LTS hardy Not in release

Notes


mdeslaur

code is different in precise+, looks ok

References

Related Ubuntu Security Notices (USN)

    • USN-1464-1
    • Ubuntu Single Sign On Client vulnerability
    • 6 June 2012

Other references