CVE-2011-3634
published 2014-03-01CVE-2011-3634: methods/https.cc in apt before 0.8.11 accepts connections when the certificate host name fails validation and Verify-Host is enabled, which allows…
PriorityP412low2.6CVSS 2.0
AVNACHAuNCPINAN
EPSS
0.80%
52.3th percentile
methods/https.cc in apt before 0.8.11 accepts connections when the certificate host name fails validation and Verify-Host is enabled, which allows man-in-the-middle attackers to obtain repository credentials via unspecified vectors.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | advanced_package_tool | <= 0.8.10.3 | — |
| debian | advanced_package_tool | — | — |
| debian | advanced_package_tool | — | — |
| debian | advanced_package_tool | — | — |
| debian | advanced_package_tool | — | — |
| debian | advanced_package_tool | — | — |
| debian | apt | < apt 0.8.11 (bookworm) | apt 0.8.11 (bookworm) |
| debian | apt | >= 0 < 0.8.11 | 0.8.11 |
| debian | apt | >= 0 < 0.8.11 | 0.8.11 |
| debian | apt | >= 0 < 0.8.11 | 0.8.11 |
| debian | apt | >= 0 < 0.8.11 | 0.8.11 |
CVSS provenance
nvdv2.02.6LOWAV:N/AC:H/Au:N/C:P/I:N/A:N
osv2.6LOW
vendor_debian2.6LOW
vendor_ubuntu2.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rgc6-vjp8-p4rv: methods/https
ghsa_unreviewed·2022-05-13
CVE-2011-3634 [LOW] CWE-200 GHSA-rgc6-vjp8-p4rv: methods/https
methods/https.cc in apt before 0.8.11 accepts connections when the certificate host name fails validation and Verify-Host is enabled, which allows man-in-the-middle attackers to obtain repository credentials via unspecified vectors.
OSV
CVE-2011-3634: methods/https
osv·2014-03-01·CVSS 2.6
CVE-2011-3634 [LOW] CVE-2011-3634: methods/https
methods/https.cc in apt before 0.8.11 accepts connections when the certificate host name fails validation and Verify-Host is enabled, which allows man-in-the-middle attackers to obtain repository credentials via unspecified vectors.
Ubuntu
APT vulnerability
vendor_ubuntu·2011-11-28·CVSS 2.6
CVE-2011-3634 [LOW] APT vulnerability
Title: APT vulnerability
Summary: APT could be made to expose sensitive information over the network.
It was discovered that APT incorrectly handled the Verify-Host
configuration option. If a remote attacker were able to perform a
machine-in-the-middle attack, this flaw could potentially be used to steal
repository credentials. This issue only affected Ubuntu 10.04 LTS and
10.10. (CVE-2011-3634)
USN-1215-1 fixed a vulnerability in APT by disabling the apt-key net-update
option. This update re-enables the option with corrected verification.
Original advisory details:
It was discovered that the apt-key utility incorrectly verified GPG
keys when downloaded via the net-update option. If a remote attacker were
able to perform a machine-in-the-middle attack, this flaw could potentially be
use
Debian
CVE-2011-3634: apt - methods/https.cc in apt before 0.8.11 accepts connections when the certificate h...
vendor_debian·2011·CVSS 2.6
CVE-2011-3634 [LOW] CVE-2011-3634: apt - methods/https.cc in apt before 0.8.11 accepts connections when the certificate h...
methods/https.cc in apt before 0.8.11 accepts connections when the certificate host name fails validation and Verify-Host is enabled, which allows man-in-the-middle attackers to obtain repository credentials via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 0.8.11)
bullseye: resolved (fixed in 0.8.11)
forky: resolved (fixed in 0.8.11)
sid: resolved (fixed in 0.8.11)
trixie: resolved (fixed in 0.8.11)
No detection rules found.
No public exploits indexed.
http://people.canonical.com/~ubuntu-security/cve/2011/CVE-2011-3634.htmlhttp://www.ubuntu.com/usn/USN-1283-1https://alioth.debian.org/plugins/scmgit/cgi-bin/gitweb.cgi?p=apt/apt.git%3Ba=blob%3Bf=debian/changelog%3Bhb=HEADhttps://bugs.launchpad.net/ubuntu/+source/apt/+bug/868353http://people.canonical.com/~ubuntu-security/cve/2011/CVE-2011-3634.htmlhttp://www.ubuntu.com/usn/USN-1283-1https://alioth.debian.org/plugins/scmgit/cgi-bin/gitweb.cgi?p=apt/apt.git%3Ba=blob%3Bf=debian/changelog%3Bhb=HEADhttps://bugs.launchpad.net/ubuntu/+source/apt/+bug/868353
2014-03-01
Published