CVE-2011-4405
Last modified
CVE-2011-4405 is a vulnerability of currently unknown severity. The cupshelpers scripts in system-config-printer in Ubuntu 11.04 and 11.10, as used by the automatic printer driver download service, uses an "insecure connection" for queries to the OpenPrinting database, which allows remote attackers to execute arbitrary code via a man-in-the-middle (MITM) attack that modifies packages or repositories.. EPSS estimates a 3.49% chance of exploitation in the next 30 days.
Description
The cupshelpers scripts in system-config-printer in Ubuntu 11.04 and 11.10, as used by the automatic printer driver download service, uses an "insecure connection" for queries to the OpenPrinting database, which allows remote attackers to execute arbitrary code via a man-in-the-middle (MITM) attack that modifies packages or repositories.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Canonical | Ubuntu Linux | 11.04 |
| Canonical | Ubuntu Linux | 11.10 |
References
- http://secunia.com/advisories/46909Vendor Advisory
- http://secunia.com/advisories/46909Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2011-4405?
How severe is CVE-2011-4405?
How do I fix CVE-2011-4405?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2011
- CVE-2011-4399Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2011-4400Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2011-4401Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2011-4402Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2011-4403Multiple cross-site request forgery (CSRF) vulnerabilities i…
- CVE-2011-4404The default configuration of the HTTP server in Jetty in vSp…
- CVE-2011-4406The Ubuntu AccountsService package before 0.6.14-1git1ubuntu…
- CVE-2011-4407ppa.py in Software Properties before 0.81.13.3 does not vali…
- CVE-2011-4408The Single Sign On Client (ubuntu-sso-client) for Ubuntu 11.…
- CVE-2011-4409The Ubuntu One Client for Ubuntu 10.04 LTS, 11.04, 11.10, an…
- CVE-2011-4410Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2011-4411Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
Are you affected by CVE-2011-4405?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
