Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-1000033

Опубликовано: 25 окт. 2016
Источник: debian
EPSS Низкий

Описание

Shotwell version 0.22.0 (and possibly other versions) is vulnerable to a TLS/SSL certification validation flaw resulting in a potential for man in the middle attacks.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
shotwellfixed0.22.0-3package
shotwellno-dsajessiepackage
shotwellno-dsawheezypackage
shotwellno-dsasqueezepackage

Примечания

  • https://www.openwall.com/lists/oss-security/2015/12/04/4

  • https://bugzilla.gnome.org/show_bug.cgi?id=754488

EPSS

Процентиль: 54%
0.00849
Низкий

Связанные уязвимости

CVSS3: 3.7
ubuntu
почти 10 лет назад

Shotwell version 0.22.0 (and possibly other versions) is vulnerable to a TLS/SSL certification validation flaw resulting in a potential for man in the middle attacks.

CVSS3: 3.1
redhat
почти 11 лет назад

Shotwell version 0.22.0 (and possibly other versions) is vulnerable to a TLS/SSL certification validation flaw resulting in a potential for man in the middle attacks.

CVSS3: 3.7
nvd
почти 10 лет назад

Shotwell version 0.22.0 (and possibly other versions) is vulnerable to a TLS/SSL certification validation flaw resulting in a potential for man in the middle attacks.

CVSS3: 3.7
github
больше 4 лет назад

Shotwell version 0.22.0 (and possibly other versions) is vulnerable to a TLS/SSL certification validation flaw resulting in a potential for man in the middle attacks.

EPSS

Процентиль: 54%
0.00849
Низкий