Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-1000033

Опубликовано: 02 сент. 2015
Источник: redhat
CVSS3: 3.1
CVSS2: 2.6
EPSS Низкий

Описание

Shotwell version 0.22.0 (and possibly other versions) is vulnerable to a TLS/SSL certification validation flaw resulting in a potential for man in the middle attacks.

It was discovered that shotwell did not validate TLS certificates when publishing photos to online service. A man-in-the-middle attacker could intercept requests and provide crafted responses, obtaining users' photos and potentially sensitive data.

Отчет

Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7shotwellWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-295
https://bugzilla.redhat.com/show_bug.cgi?id=1291361shotwell: TLS certificates are not validated when publishing photos to external services

EPSS

Процентиль: 61%
0.00412
Низкий

3.1 Low

CVSS3

2.6 Low

CVSS2

Связанные уязвимости

CVSS3: 3.7
ubuntu
больше 9 лет назад

Shotwell version 0.22.0 (and possibly other versions) is vulnerable to a TLS/SSL certification validation flaw resulting in a potential for man in the middle attacks.

CVSS3: 3.7
nvd
больше 9 лет назад

Shotwell version 0.22.0 (and possibly other versions) is vulnerable to a TLS/SSL certification validation flaw resulting in a potential for man in the middle attacks.

CVSS3: 3.7
debian
больше 9 лет назад

Shotwell version 0.22.0 (and possibly other versions) is vulnerable to ...

CVSS3: 3.7
github
больше 3 лет назад

Shotwell version 0.22.0 (and possibly other versions) is vulnerable to a TLS/SSL certification validation flaw resulting in a potential for man in the middle attacks.

EPSS

Процентиль: 61%
0.00412
Низкий

3.1 Low

CVSS3

2.6 Low

CVSS2