Описание
Simple Streams (simplestreams) does not properly verify the GPG signatures of disk image files, which allows remote mirror servers to spoof disk images and have unspecified other impact via a 403 (aka Forbidden) response.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | released | 0.1.0~bzr400-0ubuntu1 |
| esm-infra-legacy/trusty | released | 0.1.0~bzr341-0ubuntu2.2 |
| precise | DNE | |
| trusty | released | 0.1.0~bzr341-0ubuntu2.2 |
| trusty/esm | released | 0.1.0~bzr341-0ubuntu2.2 |
| upstream | needs-triage | |
| vivid | released | 0.1.0~bzr354-0ubuntu1.15.04.1 |
Показывать по
6.8 Medium
CVSS2
Связанные уязвимости
Simple Streams (simplestreams) does not properly verify the GPG signatures of disk image files, which allows remote mirror servers to spoof disk images and have unspecified other impact via a 403 (aka Forbidden) response.
Simple Streams (simplestreams) does not properly verify the GPG signatures of disk image files, which allows remote mirror servers to spoof disk images and have unspecified other impact via a 403 (aka Forbidden) response.
Уязвимость операционной системы Ubuntu, позволяющая нарушителю использовать зеркальный сервер для подмены образов дисков
6.8 Medium
CVSS2