Lucene search

K
ubuntucveUbuntu.comUB:CVE-2013-2037
HistoryMay 02, 2013 - 12:00 a.m.

CVE-2013-2037

2013-05-0200:00:00
ubuntu.com
ubuntu.com
8

2.6 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:N/I:P/A:N

0.002 Low

EPSS

Percentile

52.9%

httplib2 0.7.2, 0.8, and earlier, after an initial connection is made, does
not verify that the server hostname matches a domain name in the subject’s
Common Name (CN) or subjectAltName field of the X.509 certificate, which
allows man-in-the-middle attackers to spoof SSL servers via an arbitrary
valid certificate.

Bugs

Notes

Author Note
mdeslaur upstream hasn’t taken fix as of 2013-09-03 Debian added it to 0.8-2
OSVersionArchitecturePackageVersionFilename
ubuntu10.04noarchpython-httplib2< 0.7.2-1ubuntu2~0.10.04.2UNKNOWN
ubuntu12.04noarchpython-httplib2< 0.7.2-1ubuntu2.1UNKNOWN
ubuntu12.10noarchpython-httplib2< 0.7.4-2ubuntu0.1UNKNOWN
ubuntu13.04noarchpython-httplib2< 0.7.7-1ubuntu0.1UNKNOWN

2.6 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:N/I:P/A:N

0.002 Low

EPSS

Percentile

52.9%