Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-12855

Опубликовано: 16 июн. 2019
Источник: debian
EPSS Низкий

Описание

In words.protocols.jabber.xmlstream in Twisted through 19.2.1, XMPP support did not verify certificates when used with TLS, allowing an attacker to MITM connections.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
twistedfixed18.9.0-7package
twistedfixed18.9.0-3+deb10u1busterpackage
twistedno-dsastretchpackage
twistedno-dsajessiepackage

Примечания

  • https://github.com/twisted/twisted/pull/1147

  • https://twistedmatrix.com/trac/ticket/9561

EPSS

Процентиль: 76%
0.01809
Низкий

Связанные уязвимости

CVSS3: 7.4
ubuntu
около 7 лет назад

In words.protocols.jabber.xmlstream in Twisted through 19.2.1, XMPP support did not verify certificates when used with TLS, allowing an attacker to MITM connections.

CVSS3: 7.4
redhat
около 7 лет назад

In words.protocols.jabber.xmlstream in Twisted through 19.2.1, XMPP support did not verify certificates when used with TLS, allowing an attacker to MITM connections.

CVSS3: 7.4
nvd
около 7 лет назад

In words.protocols.jabber.xmlstream in Twisted through 19.2.1, XMPP support did not verify certificates when used with TLS, allowing an attacker to MITM connections.

CVSS3: 7.4
msrc
около 5 лет назад

Описание отсутствует

suse-cvrf
почти 7 лет назад

Security update for python-Twisted

EPSS

Процентиль: 76%
0.01809
Низкий