CVE-2014-3495
published 2019-12-13CVE-2014-3495: duplicity 0.6.24 has improper verification of SSL certificates
PriorityP434high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.94%
57.5th percentile
duplicity 0.6.24 has improper verification of SSL certificates
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | duplicity | < duplicity 0.6.21-1 (bookworm) | duplicity 0.6.21-1 (bookworm) |
| debian | duplicity | — | — |
| duplicity | duplicity | — | — |
| duplicity | duplicity | >= 0 < 0.6.21-1 | 0.6.21-1 |
| duplicity | duplicity | >= 0 < 0.6.21-1 | 0.6.21-1 |
| duplicity | duplicity | >= 0 < 0.6.21-1 | 0.6.21-1 |
| duplicity | duplicity | >= 0 < 0.6.21-1 | 0.6.21-1 |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_debian7.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2014-3495: duplicity - duplicity 0.6.24 has improper verification of SSL certificates
vendor_debian·2014·CVSS 7.5
CVE-2014-3495 [HIGH] CVE-2014-3495: duplicity - duplicity 0.6.24 has improper verification of SSL certificates
duplicity 0.6.24 has improper verification of SSL certificates
Scope: local
bookworm: resolved (fixed in 0.6.21-1)
bullseye: resolved (fixed in 0.6.21-1)
forky: resolved (fixed in 0.6.21-1)
sid: resolved (fixed in 0.6.21-1)
trixie: resolved (fixed in 0.6.21-1)
GHSA
GHSA-2xxp-9232-mwj8: duplicity 0
ghsa_unreviewed·2022-05-17
CVE-2014-3495 [HIGH] CWE-295 GHSA-2xxp-9232-mwj8: duplicity 0
duplicity 0.6.24 has improper verification of SSL certificates
OSV
CVE-2014-3495: duplicity 0
osv·2019-12-13·CVSS 7.5
CVE-2014-3495 [HIGH] CVE-2014-3495: duplicity 0
duplicity 0.6.24 has improper verification of SSL certificates
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-3495 duplicity: improper verification of SSL certificates [fedora-all]
bugzilla·2014-06-16·CVSS 7.5
CVE-2014-3495 [HIGH] CVE-2014-3495 duplicity: improper verification of SSL certificates [fedora-all]
CVE-2014-3495 duplicity: improper verification of SSL certificates [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
NOTE: this issue affects multipl
Bugzilla
CVE-2014-3495 duplicity: improper verification of SSL certificates [epel-all]
bugzilla·2014-06-16·CVSS 7.5
CVE-2014-3495 [HIGH] CVE-2014-3495 duplicity: improper verification of SSL certificates [epel-all]
CVE-2014-3495 duplicity: improper verification of SSL certificates [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
NOTE: this issue affects mult
Bugzilla
CVE-2014-3495 duplicity: improper verification of SSL certificates
bugzilla·2014-06-16·CVSS 7.5
CVE-2014-3495 [HIGH] CVE-2014-3495 duplicity: improper verification of SSL certificates
CVE-2014-3495 duplicity: improper verification of SSL certificates
Eric Christensen of Red Hat Product Security reported [1] that Duplicity did not handle wildcard certificates properly. If Duplicity were to connect to a remote host that used a wildcard certificate, and the hostname does not match the wildcard, it would still consider the connection valid. The example of which is provided:
$ openssl s_client -connect s3-1-w.amazonaws.com:443 -crlf
CONNECTED(00000003)
depth=3 C = US, O = "VeriSign, Inc.", OU = Class 3 Public Primary Certification Authority
verify return:1
depth=2 C = US, O = "VeriSign, Inc.", OU = VeriSign Trust Network, OU = "(c) 2006 VeriSign, Inc. - For authorized use only", CN = VeriSign Class 3 Public Primary Certification Authority - G5
verify return:1
depth=1 C = U
https://access.redhat.com/security/cve/cve-2014-3495https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2014-3495https://bugzilla.suse.com/show_bug.cgi?id=CVE-2014-3495https://security-tracker.debian.org/tracker/CVE-2014-3495https://access.redhat.com/security/cve/cve-2014-3495https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2014-3495https://bugzilla.suse.com/show_bug.cgi?id=CVE-2014-3495https://security-tracker.debian.org/tracker/CVE-2014-3495
2019-12-13
Published