Activity log for bug #701378

Date Who What changed Old value New value Message
2011-01-11 08:20:02 nodata bug added bug
2011-01-11 15:25:57 Kees Cook description Binary package hint: update-manager-core I think update-manager has a security problem: # grep URI /etc/update-manager/meta-release | head -2 URI = http://changelogs.ubuntu.com/meta-release URI_LTS = http://changelogs.ubuntu.com/meta-release-lts Changelogs are checked over the url: http://changelogs.ubuntu.com/meta-release where you will find something like this: Dist: maverick [..] UpgradeTool: http://archive.ubuntu.com/ubuntu/dists/maverick-updates/main/dist-upgrader-all/current/maverick.tar.gz UpgradeToolSignature: http://archive.ubuntu.com/ubuntu/dists/maverick-updates/main/dist-upgrader-all/current/maverick.tar.gz.gpg Presumably, the UpgradeToolSignature is used to verify the UpgradeTool. So update-manager does two things: * Gets a key that verifies a file. * Get a file. * Checks the key verifies the file. But because this is happening over http without ssl, the key or the file or both can be replaced. Binary package hint: update-manager-core I think update-manager has a security problem: # grep URI /etc/update-manager/meta-release | head -2 URI = http://changelogs.ubuntu.com/meta-release URI_LTS = http://changelogs.ubuntu.com/meta-release-lts Changelogs are checked over the url: http://changelogs.ubuntu.com/meta-release where you will find something like this: Dist: maverick [..] UpgradeTool: http://archive.ubuntu.com/ubuntu/dists/maverick-updates/main/dist-upgrader-all/current/maverick.tar.gz UpgradeToolSignature: http://archive.ubuntu.com/ubuntu/dists/maverick-updates/main/dist-upgrader-all/current/maverick.tar.gz.gpg Presumably, the UpgradeToolSignature is used to verify the UpgradeTool. So update-manager does two things: * Gets a signature that verifies a file. * Get a file. * Checks the signature verifies the file. But because this is happening over http without ssl, the signature or the file or both can be replaced.
2011-01-11 15:27:05 Kees Cook update-manager-core (Ubuntu): importance Undecided Wishlist
2011-01-11 15:27:07 Kees Cook update-manager-core (Ubuntu): status New Confirmed
2011-01-11 15:27:16 Kees Cook visibility private public
2011-12-15 19:48:08 Walter Garcia-Fontes affects update-manager-core (Ubuntu) update-manager (Ubuntu)
2019-03-26 22:05:05 Brian Murray marked as duplicate 1744318