Lucene search

K
cveRedhatCVE-2007-6746
HistoryMay 21, 2013 - 6:55 p.m.

CVE-2007-6746

2013-05-2118:55:01
CWE-20
redhat
web.nvd.nist.gov
32
telepathy-idle
ssl
certificate validation
man-in-the-middle attack
cve-2007-6746

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

AI Score

6.3

Confidence

Low

EPSS

0.002

Percentile

58.6%

telepathy-idle before 0.1.15 does not verify (1) that the issuer is a trusted CA, (2) that the server hostname matches a domain name in the subject’s Common Name (CN), or (3) the expiration date of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

Affected configurations

Nvd
Node
canonicaltelepathy-idleRange0.1.14.1
OR
canonicaltelepathy-idleMatch0.1.10.1
OR
canonicaltelepathy-idleMatch0.1.11.1
OR
canonicaltelepathy-idleMatch0.1.11.2
OR
canonicaltelepathy-idleMatch0.1.12.1
OR
canonicaltelepathy-idleMatch0.1.14
OR
canonicalubuntu_linuxMatch12.04-lts
OR
canonicalubuntu_linuxMatch12.10
OR
canonicalubuntu_linuxMatch13.04
VendorProductVersionCPE
canonicaltelepathy-idle*cpe:2.3:a:canonical:telepathy-idle:*:*:*:*:*:*:*:*
canonicaltelepathy-idle0.1.10.1cpe:2.3:a:canonical:telepathy-idle:0.1.10.1:*:*:*:*:*:*:*
canonicaltelepathy-idle0.1.11.1cpe:2.3:a:canonical:telepathy-idle:0.1.11.1:*:*:*:*:*:*:*
canonicaltelepathy-idle0.1.11.2cpe:2.3:a:canonical:telepathy-idle:0.1.11.2:*:*:*:*:*:*:*
canonicaltelepathy-idle0.1.12.1cpe:2.3:a:canonical:telepathy-idle:0.1.12.1:*:*:*:*:*:*:*
canonicaltelepathy-idle0.1.14cpe:2.3:a:canonical:telepathy-idle:0.1.14:*:*:*:*:*:*:*
canonicalubuntu_linux12.04cpe:2.3:o:canonical:ubuntu_linux:12.04:-:lts:*:*:*:*:*
canonicalubuntu_linux12.10cpe:2.3:o:canonical:ubuntu_linux:12.10:*:*:*:*:*:*:*
canonicalubuntu_linux13.04cpe:2.3:o:canonical:ubuntu_linux:13.04:*:*:*:*:*:*:*

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

AI Score

6.3

Confidence

Low

EPSS

0.002

Percentile

58.6%