CVE-2011-3152 describes a critical vulnerability in Ubuntu's Update Manager (DistUpgrade/DistUpgradeFetcherCore.py) versions 0.87.31.1 through 0.152.25.5, impacting Ubuntu 8.04 to 11.10. The flaw stems from a lack of GPG signature verification before extracting upgrade tarballs. This allows unauthenticated man-in-the-middle attackers to perform directory traversal for arbitrary file creation/overwrite or bypass authentication via crafted meta-release files. While rated with a CVSS score of 6.4, indicating moderate severity, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1\:0.87.24CPE matchmatch criteria | cpe:2.3:a:canonical:update-manager:*:*:*:*:*:*:*:* | ||
1\:0.134.7CPE matchmatch criteria | cpe:2.3:a:canonical:update-manager:1\:0.134.7:*:*:*:*:*:*:* | ||
1\:0.142.19CPE matchmatch criteria | cpe:2.3:a:canonical:update-manager:1\:0.142.19:*:*:*:*:*:*:* | ||
1\:0.150CPE matchmatch criteria | cpe:2.3:a:canonical:update-manager:1\:0.150:*:*:*:*:*:*:* | ||
1\:0.152.25CPE matchmatch criteria | cpe:2.3:a:canonical:update-manager:1\:0.152.25:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.