Vulnerability Name: | CVE-2015-1337 (CCN-109418) | ||||||||
Assigned: | 2015-08-20 | ||||||||
Published: | 2015-08-20 | ||||||||
Updated: | 2015-10-09 | ||||||||
Summary: | Simple Streams (simplestreams) does not properly verify the GPG signatures of disk image files, which allows remote mirror servers to spoof disk images and have unspecified other impact via a 403 (aka Forbidden) response. | ||||||||
CVSS v3 Severity: | 4.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N) 3.8 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C)
| ||||||||
CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-20 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2015-1337 Source: UBUNTU Type: UNKNOWN USN-2746-1 Source: CCN Type: USN-2746-1: Simple Streams vulnerability Ubuntu Security Notice USN-2746-1 Source: UBUNTU Type: UNKNOWN USN-2746-2 Source: CCN Type: Launchpad #1487004 Malicious server can bypass gpg verification and inject malicious images Source: CONFIRM Type: Exploit https://bugs.launchpad.net/ubuntu/%2Bsource/simplestreams/%2Bbug/1487004 Source: XF Type: UNKNOWN simple-streams-cve20151337-spoofing(109418) Source: CCN Type: WhiteSource Vulnerability Database CVE-2015-1337 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: ![]() | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |