PT-2014-2155 · Debian · Apt

·

CVE-2011-3634

·

Published

2014-02-28

·

Updated

2023-02-13

CVSS v2.0

2.6

Low

VectorAV:N/AC:H/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions apt versions prior to 0.8.11
Description The issue allows man-in-the-middle attackers to obtain repository credentials via unspecified vectors when the certificate host name fails validation and Verify-Host is enabled.
Recommendations For versions prior to 0.8.11, update to version 0.8.11 or later to resolve the issue. As a temporary workaround, consider disabling the use of HTTPS connections until a patch is available. Restrict access to sensitive repository credentials to minimize the risk of exploitation.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-3634
DLA-0005-1

Affected Products

Apt