Comment 13 for bug 882055

Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package ubuntu-sso-client - 1.4.1-0ubuntu1.1

---------------
ubuntu-sso-client (1.4.1-0ubuntu1.1) oneiric-security; urgency=low

  * SECURITY UPDATE: MITM via incorrect ssl cert validation (LP: #882055)
    - debian/patches/CVE-2011-4408.patch: use pycurl instead of urllib2 in
      ubuntu_sso/account.py,
      ubuntu_sso/credentials.py,
      ubuntu_sso/tests/test_credentials.py,
      ubuntu_sso/utils/curllib.py,
      ubuntu_sso/utils/tests/test_curllib.py.
    - debian/control: add python-pycurl dependency.
    - CVE-2011-4408
 -- Marc Deslauriers <email address hidden> Fri, 25 May 2012 10:32:37 -0400