Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2007-6746

Опубликовано: 21 мая 2013
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 5.8

Описание

telepathy-idle before 0.1.15 does not verify (1) that the issuer is a trusted CA, (2) that the server hostname matches a domain name in the subject's Common Name (CN), or (3) the expiration date of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

РелизСтатусПримечание
devel

not-affected

0.1.15-1
hardy

ignored

end of life
lucid

ignored

end of life
oneiric

ignored

end of life
precise

released

0.1.11-2ubuntu0.1
quantal

released

0.1.12-1ubuntu0.1
raring

released

0.1.14-1ubuntu0.1
upstream

released

0.1.15-1

Показывать по

EPSS

Процентиль: 48%
0.0025
Низкий

5.8 Medium

CVSS2

Связанные уязвимости

nvd
больше 12 лет назад

telepathy-idle before 0.1.15 does not verify (1) that the issuer is a trusted CA, (2) that the server hostname matches a domain name in the subject's Common Name (CN), or (3) the expiration date of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

debian
больше 12 лет назад

telepathy-idle before 0.1.15 does not verify (1) that the issuer is a ...

github
больше 3 лет назад

telepathy-idle before 0.1.15 does not verify (1) that the issuer is a trusted CA, (2) that the server hostname matches a domain name in the subject's Common Name (CN), or (3) the expiration date of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

EPSS

Процентиль: 48%
0.0025
Низкий

5.8 Medium

CVSS2