PT-2015-2247 · Canonical · Simple Streams+1

Racb

+1

·

Published

2015-09-24

·

Updated

2015-10-09

·

CVE-2015-1337

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Simple Streams (simplestreams) (affected versions not specified)
Description The issue is related to the improper verification of GPG signatures of disk image files. This allows remote mirror servers to spoof disk images, potentially having other unspecified impacts, via a 403 response. The vulnerability can be exploited by a remote attacker using a mirror server to substitute disk images.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-11601
CVE-2015-1337
USN-2746-1
USN-2746-2

Affected Products

Simple Streams
Ubuntu