Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-3522

Опубликовано: 19 авг. 2014
Источник: ubuntu
Приоритет: medium
CVSS2: 4

Описание

The Serf RA layer in Apache Subversion 1.4.0 through 1.7.x before 1.7.18 and 1.8.x before 1.8.10 does not properly handle wildcards in the Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.

РелизСтатусПримечание
devel

released

1.8.10-1ubuntu1
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [1.8.8-1ubuntu3.1]]
lucid

ignored

end of life
precise

released

1.6.17dfsg-3ubuntu3.4
trusty

released

1.8.8-1ubuntu3.1
trusty/esm

DNE

trusty was released [1.8.8-1ubuntu3.1]
upstream

released

1.7.10,1.8.10

Показывать по

4 Medium

CVSS2

Связанные уязвимости

redhat
около 11 лет назад

The Serf RA layer in Apache Subversion 1.4.0 through 1.7.x before 1.7.18 and 1.8.x before 1.8.10 does not properly handle wildcards in the Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.

nvd
около 11 лет назад

The Serf RA layer in Apache Subversion 1.4.0 through 1.7.x before 1.7.18 and 1.8.x before 1.8.10 does not properly handle wildcards in the Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.

debian
около 11 лет назад

The Serf RA layer in Apache Subversion 1.4.0 through 1.7.x before 1.7. ...

github
больше 3 лет назад

The Serf RA layer in Apache Subversion 1.4.0 through 1.7.x before 1.7.18 and 1.8.x before 1.8.10 does not properly handle wildcards in the Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.

fstec
около 11 лет назад

Уязвимость программного обеспечения Apache Subversion, позволяющая удаленному злоумышленнику нарушить конфиденциальность и целостность защищаемой информации

4 Medium

CVSS2