Lucene search

K
ubuntucveUbuntu.comUB:CVE-2018-9127
HistoryApr 02, 2018 - 12:00 a.m.

CVE-2018-9127

2018-04-0200:00:00
ubuntu.com
ubuntu.com
11

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

51.4%

Botan 2.2.0 - 2.4.0 (fixed in 2.5.0) improperly handled wildcard
certificates and could accept certain certificates as valid for hostnames
when, under RFC 6125 rules, they should not match. This only affects
certificates issued to the same domain as the host, so to impersonate a
host one must already have a wildcard certificate matching other hosts in
the same domain. For example, b*.example.com would match some hostnames
that do not begin with a ‘b’ character.

Bugs

OSVersionArchitecturePackageVersionFilename
ubuntu20.04noarchbotan< anyUNKNOWN
ubuntu22.04noarchbotan< anyUNKNOWN

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

51.4%