CVE-2011-4407
EPSS 0.63%
Description
ppa.py in Software Properties before 0.81.13.3 does not validate the server certificate when downloading PPA GPG key fingerprints, which allows man-in-the-middle (MITM) attackers to spoof GPG keys for a package repository.
How to fix CVE-2011-4407
To remediate CVE-2011-4407, upgrade the affected package to a fixed version below.
- Debian/software-properties—upgrade to 0.76.7debian2+nmu2 or later
Is CVE-2011-4407 being exploited?
Low — EPSS is 0.6%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 0.76.7debian2+nmu2