Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rgc6-vjp8-p4rv

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью

Описание

methods/https.cc in apt before 0.8.11 accepts connections when the certificate host name fails validation and Verify-Host is enabled, which allows man-in-the-middle attackers to obtain repository credentials via unspecified vectors.

methods/https.cc in apt before 0.8.11 accepts connections when the certificate host name fails validation and Verify-Host is enabled, which allows man-in-the-middle attackers to obtain repository credentials via unspecified vectors.

EPSS

Процентиль: 37%
0.00163
Низкий

Дефекты

CWE-200

Связанные уязвимости

ubuntu
почти 12 лет назад

methods/https.cc in apt before 0.8.11 accepts connections when the certificate host name fails validation and Verify-Host is enabled, which allows man-in-the-middle attackers to obtain repository credentials via unspecified vectors.

nvd
почти 12 лет назад

methods/https.cc in apt before 0.8.11 accepts connections when the certificate host name fails validation and Verify-Host is enabled, which allows man-in-the-middle attackers to obtain repository credentials via unspecified vectors.

debian
почти 12 лет назад

methods/https.cc in apt before 0.8.11 accepts connections when the cer ...

EPSS

Процентиль: 37%
0.00163
Низкий

Дефекты

CWE-200