296,202
Total vulnerabilities in the database
methods/https.cc in apt before 0.8.11 accepts connections when the certificate host name fails validation and Verify-Host is enabled, which allows man-in-the-middle attackers to obtain repository credentials via unspecified vectors.
Software | From | Fixed in |
---|---|---|
canonical / ubuntu_linux | 10.10 | 10.10.x |
canonical / ubuntu_linux | 8.04 | 8.04.x |
canonical / ubuntu_linux | 11.04 | 11.04.x |
canonical / ubuntu_linux | 10.04 | 10.04.x |
debian / advanced_package_tool | 0.8.0-pre1 | 0.8.0-pre1.x |
debian / advanced_package_tool | 0.8.0 | 0.8.0.x |
debian / advanced_package_tool | 0.8.0-pre2 | 0.8.0-pre2.x |
debian / advanced_package_tool | 0.8.1 | 0.8.1.x |
debian / advanced_package_tool | 0.8.10 | 0.8.10.x |
debian / advanced_package_tool | 0.8.10.1 | 0.8.10.1.x |
debian / advanced_package_tool | 0.8.10.2 | 0.8.10.2.x |
debian / advanced_package_tool | - | 0.8.10.3.x |