Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-3522

Опубликовано: 19 авг. 2014
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4

Описание

The Serf RA layer in Apache Subversion 1.4.0 through 1.7.x before 1.7.18 and 1.8.x before 1.8.10 does not properly handle wildcards in the Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.

РелизСтатусПримечание
devel

released

1.8.10-1ubuntu1
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [1.8.8-1ubuntu3.1]]
lucid

ignored

end of life
precise

released

1.6.17dfsg-3ubuntu3.4
trusty

released

1.8.8-1ubuntu3.1
trusty/esm

DNE

trusty was released [1.8.8-1ubuntu3.1]
upstream

released

1.7.10,1.8.10

Показывать по

EPSS

Процентиль: 81%
0.01595
Низкий

4 Medium

CVSS2

Связанные уязвимости

redhat
около 11 лет назад

The Serf RA layer in Apache Subversion 1.4.0 through 1.7.x before 1.7.18 and 1.8.x before 1.8.10 does not properly handle wildcards in the Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.

nvd
почти 11 лет назад

The Serf RA layer in Apache Subversion 1.4.0 through 1.7.x before 1.7.18 and 1.8.x before 1.8.10 does not properly handle wildcards in the Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.

debian
почти 11 лет назад

The Serf RA layer in Apache Subversion 1.4.0 through 1.7.x before 1.7. ...

github
больше 3 лет назад

The Serf RA layer in Apache Subversion 1.4.0 through 1.7.x before 1.7.18 and 1.8.x before 1.8.10 does not properly handle wildcards in the Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.

fstec
почти 11 лет назад

Уязвимость программного обеспечения Apache Subversion, позволяющая удаленному злоумышленнику нарушить конфиденциальность и целостность защищаемой информации

EPSS

Процентиль: 81%
0.01595
Низкий

4 Medium

CVSS2