The base-files package before 5.0.0ubuntu7.1 on Ubuntu 9.10 and before 5.0.0ubuntu20.10.04.2 on Ubuntu 10.04 LTS, as shipped on Dell Latitude 2110 netbooks, does not require authentication for package installation, which allows remote archive servers and man-in-the-middle attackers to execute arbitrary code via a crafted package.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: canonical

Published: 2010-08-09T20:00:00Z

Updated: 2024-09-16T22:24:37.174Z

Reserved: 2010-03-03T00:00:00Z

Link: CVE-2010-0834

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2010-08-10T12:23:05.850

Modified: 2010-08-10T12:23:05.850

Link: CVE-2010-0834

cve-icon Redhat

No data.