Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2011-3634

Опубликовано: 01 мар. 2014
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 2.6

Описание

methods/https.cc in apt before 0.8.11 accepts connections when the certificate host name fails validation and Verify-Host is enabled, which allows man-in-the-middle attackers to obtain repository credentials via unspecified vectors.

РелизСтатусПримечание
devel

not-affected

hardy

not-affected

defaults to properly verify host name
lucid

released

0.7.25.3ubuntu9.9
maverick

released

0.8.3ubuntu7.3
natty

not-affected

0.8.13.2ubuntu4.2
oneiric

not-affected

upstream

not-affected

0.8.15.9

Показывать по

EPSS

Процентиль: 38%
0.00163
Низкий

2.6 Low

CVSS2

Связанные уязвимости

nvd
почти 12 лет назад

methods/https.cc in apt before 0.8.11 accepts connections when the certificate host name fails validation and Verify-Host is enabled, which allows man-in-the-middle attackers to obtain repository credentials via unspecified vectors.

debian
почти 12 лет назад

methods/https.cc in apt before 0.8.11 accepts connections when the cer ...

github
больше 3 лет назад

methods/https.cc in apt before 0.8.11 accepts connections when the certificate host name fails validation and Verify-Host is enabled, which allows man-in-the-middle attackers to obtain repository credentials via unspecified vectors.

EPSS

Процентиль: 38%
0.00163
Низкий

2.6 Low

CVSS2