2.6

CVE-2011-3634

methods/https.cc in apt before 0.8.11 accepts connections when the certificate host name fails validation and Verify-Host is enabled, which allows man-in-the-middle attackers to obtain repository credentials via unspecified vectors.

Data is provided by the National Vulnerability Database (NVD)
DebianAdvanced Package Tool Version <= 0.8.10.3
DebianAdvanced Package Tool Version0.8.0
DebianAdvanced Package Tool Version0.8.0 Updatepre1
DebianAdvanced Package Tool Version0.8.0 Updatepre2
DebianAdvanced Package Tool Version0.8.1
DebianAdvanced Package Tool Version0.8.10
DebianAdvanced Package Tool Version0.8.10.1
DebianAdvanced Package Tool Version0.8.10.2
CanonicalUbuntu Linux Version8.04 Update- Editionlts
CanonicalUbuntu Linux Version10.04 Update- Editionlts
CanonicalUbuntu Linux Version10.10
CanonicalUbuntu Linux Version11.04
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.16% 0.339
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 2.6 4.9 2.9
AV:N/AC:H/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.