Lucene search

K
ubuntucveUbuntu.comUB:CVE-2013-4488
HistoryOct 10, 2014 - 12:00 a.m.

CVE-2013-4488

2014-10-1000:00:00
ubuntu.com
ubuntu.com
13

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.001

Percentile

48.9%

libgadu before 1.12.0 does not verify X.509 certificates from SSL servers,
which allows man-in-the-middle attackers to spoof servers.

Bugs

Notes

Author Note
mdeslaur we build with the gnutls backend upstream certs don’t actually match host names used, so correct cert validation is difficult.

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.001

Percentile

48.9%