CVE-2014-3495: High severity Debian Duplicity vulnerability
Published Dec 13, 2019
·Updated
duplicity 0.6.24 has improper verification of SSL certificates
Affected Software
7 affected componentsFixes available
Debian Duplicity=0.6.24
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Debian Debian Linux=10.0
openSUSE openSUSE=12.3
openSUSE openSUSE=13.1
debian/duplicity
0.8.17-10.8.22-13.0.4-13.0.6.3-2
Event History
Dec 13, 2019
CVE Published
via MITRE·01:20 PM
Data Sourced
via MITRE·01:20 PM
DescriptionWeakness
Feb 18, 2026
Data Sourced
via Debian·07:08 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is CVE-2014-3495?
CVE-2014-3495 is a vulnerability in duplicity 0.6.24 that allows for improper verification of SSL certificates.
2
How does CVE-2014-3495 affect the affected software?
CVE-2014-3495 affects various versions of Debian Duplicity and Debian Debian Linux, as well as Opensuse Opensuse.
3
What is the severity of CVE-2014-3495?
CVE-2014-3495 has a severity rating of high.
4
How can I fix CVE-2014-3495?
To fix CVE-2014-3495, update to a version of duplicity that is not affected by the vulnerability.
5
Where can I find more information about CVE-2014-3495?
You can find more information about CVE-2014-3495 at the following references: [Reference 1](https://access.redhat.com/security/cve/cve-2014-3495), [Reference 2](https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2014-3495), [Reference 3](https://bugzilla.suse.com/show_bug.cgi?id=CVE-2014-3495).