Ubuntu contains a flaw related to the single sign on client. The issue is triggered due to the improper validation of certain SSL certificates. This may allow an attacker to spoof a valid server and perform a man-in-the-middle attack.
Classification
Location:
Remote / Network Access
Attack Type:
Cryptographic,
Input Manipulation
Impact:
Loss of Integrity
Solution:
Upgrade
Exploit:
Exploit Unknown
Disclosure:
Vendor Verified
OSVDB:
Web Related
Solution
Upgrade to version 1.4.1-0ubuntu1.1, 1.2.1-0ubuntu2.1, or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.