CVE-2011-3634

EUVD-2011-3593
methods/https.cc in apt before 0.8.11 accepts connections when the certificate host name fails validation and Verify-Host is enabled, which allows man-in-the-middle attackers to obtain repository credentials via unspecified vectors.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
2.6 UNKNOWN
NETWORK
HIGH
AV:N/AC:H/Au:N/C:P/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 37%
Affected Products (NVD)
VendorProductVersion
debianadvanced_package_tool
𝑥
≤ 0.8.10.3
debianadvanced_package_tool
0.8.0
debianadvanced_package_tool
0.8.0:pre1
debianadvanced_package_tool
0.8.0:pre2
debianadvanced_package_tool
0.8.1
debianadvanced_package_tool
0.8.10
debianadvanced_package_tool
0.8.10.1
debianadvanced_package_tool
0.8.10.2
canonicalubuntu_linux
8.04
canonicalubuntu_linux
10.04
canonicalubuntu_linux
10.10
canonicalubuntu_linux
11.04
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
apt
bookworm
2.6.1
fixed
bullseye
2.2.4
fixed
sid
2.9.10
fixed
trixie
2.9.10
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
apt
hardy
not-affected
lucid
Fixed 0.7.25.3ubuntu9.9
released
maverick
Fixed 0.8.3ubuntu7.3
released
natty
not-affected
oneiric
not-affected