Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2011-3634

Опубликовано: 01 мар. 2014
Источник: debian
EPSS Низкий

Описание

methods/https.cc in apt before 0.8.11 accepts connections when the certificate host name fails validation and Verify-Host is enabled, which allows man-in-the-middle attackers to obtain repository credentials via unspecified vectors.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
aptfixed0.8.11package
aptfixed0.8.10.3+squeeze2squeezepackage

Примечания

  • Minor issue, apt is only affected if apt-transport-https is installed

  • http://bazaar.launchpad.net/~donkult/apt/sid/revision/2053.1.28

  • https://bugs.launchpad.net/ubuntu/+source/apt/+bug/868353

EPSS

Процентиль: 38%
0.00163
Низкий

Связанные уязвимости

ubuntu
почти 12 лет назад

methods/https.cc in apt before 0.8.11 accepts connections when the certificate host name fails validation and Verify-Host is enabled, which allows man-in-the-middle attackers to obtain repository credentials via unspecified vectors.

nvd
почти 12 лет назад

methods/https.cc in apt before 0.8.11 accepts connections when the certificate host name fails validation and Verify-Host is enabled, which allows man-in-the-middle attackers to obtain repository credentials via unspecified vectors.

github
больше 3 лет назад

methods/https.cc in apt before 0.8.11 accepts connections when the certificate host name fails validation and Verify-Host is enabled, which allows man-in-the-middle attackers to obtain repository credentials via unspecified vectors.

EPSS

Процентиль: 38%
0.00163
Низкий