Comment 14 for bug 882055

Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package ubuntu-sso-client - 1.2.1-0ubuntu2.1

---------------
ubuntu-sso-client (1.2.1-0ubuntu2.1) natty-security; urgency=low

  * SECURITY UPDATE: MITM via incorrect ssl cert validation (LP: #882055)
    - debian/patches/CVE-2011-4408.patch: use pycurl instead of urllib2 in
      ubuntu_sso/account.py,
      ubuntu_sso/credentials.py,
      ubuntu_sso/tests/test_credentials.py,
      ubuntu_sso/utils/curllib.py,
      ubuntu_sso/utils/tests/test_curllib.py.
    - debian/control: add python-pycurl dependency.
    - CVE-2011-4408
 -- Marc Deslauriers <email address hidden> Tue, 31 Jan 2012 14:01:31 -0500