CVE-2011-3634
Publication date 28 October 2011
Last updated 24 July 2024
Ubuntu priority
methods/https.cc in apt before 0.8.11 accepts connections when the certificate host name fails validation and Verify-Host is enabled, which allows man-in-the-middle attackers to obtain repository credentials via unspecified vectors.
Status
Package | Ubuntu Release | Status |
---|---|---|
apt | 11.10 oneiric |
Not affected
|
11.04 natty |
Not affected
|
|
10.10 maverick |
Fixed 0.8.3ubuntu7.3
|
|
10.04 LTS lucid |
Fixed 0.7.25.3ubuntu9.9
|
|
8.04 LTS hardy |
Not affected
|
Patch details
Package | Patch details |
---|---|
apt |
References
Related Ubuntu Security Notices (USN)
- USN-1283-1
- APT vulnerability
- 28 November 2011