CVE-2011-3154: Canonical Ubuntu Linux
Low severity, CVSS 1.9. EPSS: 0.3% chance of exploitation in the next 30 days.
DistUpgrade/DistUpgradeViewKDE.py in Update Manager before 1:0.87.31.1, 1:0.134.x before 1:0.134.11.1, 1:0.142.x before 1:0.142.23.1, 1:0.150.x before 1:0.150.5.1, and 1:0.152.x before 1:0.152.25.5 does not properly create temporary files, which allows local users to obtain the XAUTHORITY file content for a user via a symlink attack on the temporary file.
Affected products
- Canonical Ubuntu Linux: version 8.04 only; version 10.04 only; version 10.10 only; version 11.04 only; version 11.10 only
- Canonical Update-Manager: up to and including 1\:0.87.24; version 1:0.134.7 only; version 1:0.142.19 only; version 1:0.150 only; version 1:0.152.25 only
Published 2014-04-17. Last modified 2026-06-16.