USN-1061-1: iTALC vulnerability

11 February 2011

italc vulnerability

A security issue affects these releases of Ubuntu and its derivatives:

  • Ubuntu 10.10
  • Ubuntu 10.04 LTS
  • Ubuntu 9.10

Summary

Private keys for iTALC shipped on Live DVD

Software Description

  • italc - Intelligent Teaching and Learning with Computers

Details

St├ęphane Graber discovered that the iTALC private keys shipped with the Edubuntu Live DVD were not correctly regenerated once Edubuntu was installed. If an iTALC client was installed with the vulnerable keys, a remote attacker could gain control of the system. Only systems using keys from the Edubuntu Live DVD were affected.

Update instructions

The problem can be corrected by updating your system to the following package versions:

Ubuntu 10.10
italc-client - 1:1.0.9.1-0ubuntu18.10.10.1
Ubuntu 10.04 LTS
italc-client - 1:1.0.9.1-0ubuntu18.10.04.1
Ubuntu 9.10
italc-client - 1:1.0.9.1-0ubuntu16.1

To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades.

After a standard system update, if you had originally installed from the Edubuntu Live DVD and the bad keys were found, you will need to redistribute the newly generated public keys to your iTALC clients and restart each session. For more details, see: https://wiki.ubuntu.com/iTalc/Keys

References