maas-import-pxe-files in MAAS before 13.10 does not verify the integrity of downloaded files, which allows remote attackers to modify these files via a man-in-the-middle (MITM) attack.
| Software | From | Fixed in |
|---|---|---|
| canonical / ubuntu_linux | 13.04 | 13.04.x |
| canonical / ubuntu_linux | 12.10 | 12.10.x |
| canonical / ubuntu_linux | 12.04 | 12.04.x |
| canonical / maas | 12.04.1 | 12.04.1.x |
| canonical / maas | 12.04.3 | 12.04.3.x |
| canonical / maas | - | 12.04.4.x |
| canonical / maas | 12.04.2 | 12.04.2.x |