Lucene search

K
nvd[email protected]NVD:CVE-2011-3634
HistoryMar 01, 2014 - 12:55 a.m.

CVE-2011-3634

2014-03-0100:55:04
CWE-200
web.nvd.nist.gov
4

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:H/Au:N/C:P/I:N/A:N

AI Score

6.2

Confidence

Low

EPSS

0.001

Percentile

39.8%

methods/https.cc in apt before 0.8.11 accepts connections when the certificate host name fails validation and Verify-Host is enabled, which allows man-in-the-middle attackers to obtain repository credentials via unspecified vectors.

Affected configurations

Nvd
Node
debianadvanced_package_toolRange0.8.10.3
OR
debianadvanced_package_toolMatch0.8.0
OR
debianadvanced_package_toolMatch0.8.0pre1
OR
debianadvanced_package_toolMatch0.8.0pre2
OR
debianadvanced_package_toolMatch0.8.1
OR
debianadvanced_package_toolMatch0.8.10
OR
debianadvanced_package_toolMatch0.8.10.1
OR
debianadvanced_package_toolMatch0.8.10.2
OR
canonicalubuntu_linuxMatch8.04-lts
OR
canonicalubuntu_linuxMatch10.04-lts
OR
canonicalubuntu_linuxMatch10.10
OR
canonicalubuntu_linuxMatch11.04
VendorProductVersionCPE
debianadvanced_package_tool*cpe:2.3:a:debian:advanced_package_tool:*:*:*:*:*:*:*:*
debianadvanced_package_tool0.8.0cpe:2.3:a:debian:advanced_package_tool:0.8.0:*:*:*:*:*:*:*
debianadvanced_package_tool0.8.0cpe:2.3:a:debian:advanced_package_tool:0.8.0:pre1:*:*:*:*:*:*
debianadvanced_package_tool0.8.0cpe:2.3:a:debian:advanced_package_tool:0.8.0:pre2:*:*:*:*:*:*
debianadvanced_package_tool0.8.1cpe:2.3:a:debian:advanced_package_tool:0.8.1:*:*:*:*:*:*:*
debianadvanced_package_tool0.8.10cpe:2.3:a:debian:advanced_package_tool:0.8.10:*:*:*:*:*:*:*
debianadvanced_package_tool0.8.10.1cpe:2.3:a:debian:advanced_package_tool:0.8.10.1:*:*:*:*:*:*:*
debianadvanced_package_tool0.8.10.2cpe:2.3:a:debian:advanced_package_tool:0.8.10.2:*:*:*:*:*:*:*
canonicalubuntu_linux8.04cpe:2.3:o:canonical:ubuntu_linux:8.04:-:lts:*:*:*:*:*
canonicalubuntu_linux10.04cpe:2.3:o:canonical:ubuntu_linux:10.04:-:lts:*:*:*:*:*
Rows per page:
1-10 of 121

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:H/Au:N/C:P/I:N/A:N

AI Score

6.2

Confidence

Low

EPSS

0.001

Percentile

39.8%