6.4
CVE-2007-3499
- EPSS 0.86%
- Veröffentlicht 29.06.2007 18:30:00
- Zuletzt bearbeitet 16.06.2026 22:42:10
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
SlackRoll before 8 accepts gpg exit codes other than 0 and 1 as evidence of a valid signature, which allows remote Slackware mirror sites or man-in-the-middle attackers to cause a denial of service (data inconsistency) or possibly install Trojan horse packages via malformed gpg signatures.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.86% | 0.538 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.4 | 10 | 4.9 |
AV:N/AC:L/Au:N/C:N/I:P/A:P
|
http://osvdb.org/41635
http://sourceforge.net/project/shownotes.php?release_id=518019&group_id=197236