maas-import-pxe-files in MAAS before 13.10 does not verify the integrity of downloaded files, which allows remote attackers to modify these files via a man-in-the-middle (MITM) attack.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Ubuntu_linux | Canonical | 12.04 (including) | 12.04 (including) |
| Ubuntu_linux | Canonical | 12.10 (including) | 12.10 (including) |
| Ubuntu_linux | Canonical | 13.04 (including) | 13.04 (including) |
| Maas | Ubuntu | precise | * |
| Maas | Ubuntu | quantal | * |
| Maas | Ubuntu | raring | * |