CVE-2011-3634: Infoleak
methods/https.cc in apt before 0.8.11 accepts connections when the certificate host name fails validation and Verify-Host is enabled, which allows man-in-the-middle attackers to obtain repository credentials via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-3634?
CVE-2011-3634 has been classified as a high-severity vulnerability due to the potential for man-in-the-middle attacks.
How do I fix CVE-2011-3634?
To fix CVE-2011-3634, update your apt package to version 0.8.11 or later.
Which versions of apt are affected by CVE-2011-3634?
CVE-2011-3634 affects apt versions prior to 0.8.11, including several versions such as 0.8.0 and 0.8.10.x.
What kind of attacks can CVE-2011-3634 facilitate?
CVE-2011-3634 can facilitate man-in-the-middle attacks, leading to the exposure of repository credentials.
Which operating systems are impacted by CVE-2011-3634?
CVE-2011-3634 impacts multiple versions of Ubuntu and Debian distributions that are running affected versions of apt.