Executive Summary
Summary | |
---|---|
Title | curl vulnerability |
Informations | |||
---|---|---|---|
Name | USN-484-1 | First vendor Publication | 2007-07-17 |
Vendor | Ubuntu | Last vendor Modification | 2007-07-17 |
Severity (Vendor) | N/A | Revision | N/A |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:P/I:P/A:P) | |||
---|---|---|---|
Cvss Base Score | 7.5 | Attack Range | Network |
Cvss Impact Score | 6.4 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS Ubuntu 6.10 Ubuntu 7.04 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 6.06 LTS: Ubuntu 6.10: Ubuntu 7.04: After a standard system upgrade you need to reboot your computer to effect the necessary changes. Details follow: It was discovered that the GnuTLS certificate verification methods implemented in Curl did not check for expiration and activation dates. When performing validations, tools using libcurl3-gnutls would incorrectly allow connections to sites using expired certificates. |
Original Source
Url : http://www.ubuntu.com/usn/USN-484-1 |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:20515 | |||
Oval ID: | oval:org.mitre.oval:def:20515 | ||
Title: | DSA-1333-1 curl | ||
Description: | It has been discovered that the GnuTLS certificate verification methods implemented in libcurl-gnutls, a solid, usable, and portable multi-protocol file transfer library, did not check for expired or invalid dates. | ||
Family: | unix | Class: | patch |
Reference(s): | DSA-1333-1 CVE-2007-3564 | Version: | 5 |
Platform(s): | Debian GNU/Linux 4.0 | Product(s): | curl |
Definition Synopsis: | |||
CPE : Common Platform Enumeration
OpenVAS Exploits
Date | Description |
---|---|
2009-03-23 | Name : Ubuntu Update for curl vulnerability USN-484-1 File : nvt/gb_ubuntu_USN_484_1.nasl |
2008-01-17 | Name : Debian Security Advisory DSA 1333-1 (libcurl3-gnutls) File : nvt/deb_1333_1.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
38207 | cURL/libcURL with GnuTLS SSL/TLS Certificate Access Restriction Bypass |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2007-11-10 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-484-1.nasl - Type : ACT_GATHER_INFO |
2007-07-23 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-1333.nasl - Type : ACT_GATHER_INFO |
Alert History
Date | Informations |
---|---|
2014-02-17 12:04:28 |
|