Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-45197

Опубликовано: 25 дек. 2022
Источник: debian

Описание

Slixmpp before 1.8.3 lacks SSL Certificate hostname validation in XMLStream, allowing an attacker to pose as any server in the eyes of Slixmpp.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
slixmppfixed1.8.3-1package
slixmppno-dsabullseyepackage
slixmppno-dsabusterpackage

Примечания

  • https://lab.louiz.org/poezio/slixmpp/-/commit/b60b1b985db928532f97c4f61d6fbc801f0aa7fa (slix-1.8.3)

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 3 лет назад

Slixmpp before 1.8.3 lacks SSL Certificate hostname validation in XMLStream, allowing an attacker to pose as any server in the eyes of Slixmpp.

CVSS3: 7.5
nvd
около 3 лет назад

Slixmpp before 1.8.3 lacks SSL Certificate hostname validation in XMLStream, allowing an attacker to pose as any server in the eyes of Slixmpp.

suse-cvrf
около 3 лет назад

Security update for python-slixmpp

suse-cvrf
около 3 лет назад

Security update for python-slixmpp

CVSS3: 7.5
github
около 3 лет назад

Slixmpp lacks SSL Certificate hostname validation in XMLStream