Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-29495

Опубликовано: 07 мая 2021
Источник: debian

Описание

Nim is a statically typed compiled systems programming language. In Nim standard library before 1.4.2, httpClient SSL/TLS certificate verification was disabled by default. Users can upgrade to version 1.4.2 to receive a patch or, as a workaround, set "verifyMode = CVerifyPeer" as documented.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
nimfixed1.4.2-1package
nimno-dsabusterpackage
nimno-dsastretchpackage

Примечания

  • https://github.com/nim-lang/security/security/advisories/GHSA-9vqv-2jj9-7mqr

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 4 лет назад

Nim is a statically typed compiled systems programming language. In Nim standard library before 1.4.2, httpClient SSL/TLS certificate verification was disabled by default. Users can upgrade to version 1.4.2 to receive a patch or, as a workaround, set "verifyMode = CVerifyPeer" as documented.

CVSS3: 5.9
nvd
больше 4 лет назад

Nim is a statically typed compiled systems programming language. In Nim standard library before 1.4.2, httpClient SSL/TLS certificate verification was disabled by default. Users can upgrade to version 1.4.2 to receive a patch or, as a workaround, set "verifyMode = CVerifyPeer" as documented.

CVSS3: 7.5
fstec
около 12 лет назад

Уязвимость языка программирования Nim, связанная с ошибками процедуры подтверждения подлинности сертификата, позволяющая нарушителю оказать воздействие на целостность данных

suse-cvrf
больше 3 лет назад

Security update for nim

suse-cvrf
больше 3 лет назад

Security update for nim