CVE-2011-3634
01.03.2014, 00:55
methods/https.cc in apt before 0.8.11 accepts connections when the certificate host name fails validation and Verify-Host is enabled, which allows man-in-the-middle attackers to obtain repository credentials via unspecified vectors.Enginsight
| Vendor | Product | Version |
|---|---|---|
| debian | advanced_package_tool | 𝑥 ≤ 0.8.10.3 |
| debian | advanced_package_tool | 0.8.0 |
| debian | advanced_package_tool | 0.8.0:pre1 |
| debian | advanced_package_tool | 0.8.0:pre2 |
| debian | advanced_package_tool | 0.8.1 |
| debian | advanced_package_tool | 0.8.10 |
| debian | advanced_package_tool | 0.8.10.1 |
| debian | advanced_package_tool | 0.8.10.2 |
| canonical | ubuntu_linux | 8.04 |
| canonical | ubuntu_linux | 10.04 |
| canonical | ubuntu_linux | 10.10 |
| canonical | ubuntu_linux | 11.04 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
References