2.6

CVE-2011-3634

methods/https.cc in apt before 0.8.11 accepts connections when the certificate host name fails validation and Verify-Host is enabled, which allows man-in-the-middle attackers to obtain repository credentials via unspecified vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Debian ≫ Advanced Package Tool Version <= 0.8.10.3
Debian ≫ Advanced Package Tool Version 0.8.0
Debian ≫ Advanced Package Tool Version 0.8.0 Update pre1
Debian ≫ Advanced Package Tool Version 0.8.0 Update pre2
Debian ≫ Advanced Package Tool Version 0.8.1
Debian ≫ Advanced Package Tool Version 0.8.10
Debian ≫ Advanced Package Tool Version 0.8.10.1
Debian ≫ Advanced Package Tool Version 0.8.10.2
Canonical ≫ Ubuntu Linux Version 8.04 Update - Edition lts
Canonical ≫ Ubuntu Linux Version 10.04 Update - Edition lts
Canonical ≫ Ubuntu Linux Version 10.10
Canonical ≫ Ubuntu Linux Version 11.04
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.8% 0.518
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 2.6 4.9 2.9
AV:N/AC:H/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

http://people.canonical.com/~ubuntu-security/cve/2011/CVE-2011-3634.html
http://www.ubuntu.com/usn/USN-1283-1
https://alioth.debian.org/plugins/scmgit/cgi-bin/gitweb.cgi?p=apt/apt.git%3Ba=blob%3Bf=debian/changelog%3Bhb=HEAD
https://bugs.launchpad.net/ubuntu/+source/apt/+bug/868353