Ubuntu 9.10 / 10.04 LTS / 10.10 : italc vulnerability (USN-1061-1)

Ubuntu Security Notice (C) 2011-2013 Canonical, Inc. / NASL script (C) 2013 Tenable Network Security, Inc.


Synopsis :

The remote Ubuntu host is missing a security-related patch.

Description :

Stéphane Graber discovered that the iTALC private keys shipped with
the Edubuntu Live DVD were not correctly regenerated once Edubuntu was
installed. If an iTALC client was installed with the vulnerable keys,
a remote attacker could gain control of the system. Only systems using
keys from the Edubuntu Live DVD were affected.

Solution :

Update the affected italc-client package.

Risk factor :

High / CVSS Base Score : 9.3
(CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)

Family: Ubuntu Local Security Checks

Nessus Plugin ID: 65098 ()

Bugtraq ID:

CVE ID: CVE-2011-0724