Lucene search

K
ubuntuUbuntuUSN-1948-1
HistorySep 09, 2013 - 12:00 a.m.

httplib2 vulnerability

2013-09-0900:00:00
ubuntu.com
30

2.6 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:N/I:P/A:N

6.2 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

52.9%

Releases

  • Ubuntu 13.04
  • Ubuntu 12.10
  • Ubuntu 12.04
  • Ubuntu 10.04

Packages

  • python-httplib2 - comprehensive HTTP client library written in Python

Details

It was discovered that httplib2 only validated SSL certificates on the
first request to a connection, and didn’t report validation failures on
subsequent requests. If a remote attacker were able to perform a
machine-in-the-middle attack, this flaw could possibly be exploited in certain
scenarios to alter or compromise confidential information in applications
that used the httplib2 library.

OSVersionArchitecturePackageVersionFilename
Ubuntu13.04noarchpython-httplib2< 0.7.7-1ubuntu0.1UNKNOWN
Ubuntu13.04noarchpython3-httplib2< 0.7.7-1ubuntu0.1UNKNOWN
Ubuntu12.10noarchpython-httplib2< 0.7.4-2ubuntu0.1UNKNOWN
Ubuntu12.10noarchpython3-httplib2< 0.7.4-2ubuntu0.1UNKNOWN
Ubuntu12.04noarchpython-httplib2< 0.7.2-1ubuntu2.1UNKNOWN
Ubuntu12.04noarchpython3-httplib2< 0.7.2-1ubuntu2.1UNKNOWN
Ubuntu10.04noarchpython-httplib2< 0.7.2-1ubuntu2~0.10.04.2UNKNOWN

2.6 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:N/I:P/A:N

6.2 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

52.9%