CVE-2011-3634 Information

Description

methods/https.cc in apt before 0.8.11 accepts connections when the certificate host name fails validation and Verify-Host is enabled which allows man-in-the-middle attackers to obtain repository credentials via unspecified vectors.

Reference

http://people.canonical.com/~ubuntu-security/cve/2011/CVE-2011-3634.html http://www.ubuntu.com/usn/USN-1283-1 https://alioth.debian.org/plugins/scmgit/cgi-bin/gitweb.cgi?p=apt/apt.git;a=blob;f=debian/changelog;hb=HEAD https://bugs.launchpad.net/ubuntu/+source/apt/+bug/868353

Share on: