Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2011-0724 | First vendor Publication | 2011-02-18 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 9.3 | Attack Range | Network |
Cvss Impact Score | 10 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
The Live DVD for Edubuntu 9.10, 10.04 LTS, and 10.10 does not correctly regenerate iTALC private keys after installation, which causes each installation to have the same fixed key, which allows remote attackers to gain privileges. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0724 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-310 | Cryptographic Issues |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:21293 | |||
Oval ID: | oval:org.mitre.oval:def:21293 | ||
Title: | USN-1061-1 -- italc vulnerability | ||
Description: | Stphane Graber discovered that the iTALC private keys shipped with the Edubuntu Live DVD were not correctly regenerated once Edubuntu was installed. | ||
Family: | unix | Class: | patch |
Reference(s): | USN-1061-1 CVE-2011-0724 | Version: | 5 |
Platform(s): | Ubuntu 9.10 Ubuntu 10.04 Ubuntu 10.10 | Product(s): | italc |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Hardware | 1 | |
Os | 3 |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
73303 | Edubuntu Live DVD iTALC Private Keys Regeneration Remote Privilege Escalation |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2013-03-09 | Name : The remote Ubuntu host is missing a security-related patch. File : ubuntu_USN-1061-1.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Source | Url |
---|
Alert History
Date | Informations |
---|---|
2024-11-28 23:05:59 |
|
2024-11-28 12:24:50 |
|
2020-05-23 00:27:48 |
|
2017-08-17 09:23:18 |
|
2014-02-17 11:00:31 |
|
2013-05-10 22:54:39 |
|