First published: Fri Dec 13 2019(Updated: )
duplicity 0.6.24 has improper verification of SSL certificates
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Debian Duplicity | =0.6.24 | |
Debian Debian Linux | =8.0 | |
Debian Debian Linux | =9.0 | |
Debian Debian Linux | =10.0 | |
openSUSE openSUSE | =12.3 | |
openSUSE openSUSE | =13.1 | |
debian/duplicity | 0.8.17-1 0.8.22-1 2.1.4-3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3495 is a vulnerability in duplicity 0.6.24 that allows for improper verification of SSL certificates.
CVE-2014-3495 affects various versions of Debian Duplicity and Debian Debian Linux, as well as Opensuse Opensuse.
CVE-2014-3495 has a severity rating of high.
To fix CVE-2014-3495, update to a version of duplicity that is not affected by the vulnerability.
You can find more information about CVE-2014-3495 at the following references: [Reference 1](https://access.redhat.com/security/cve/cve-2014-3495), [Reference 2](https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2014-3495), [Reference 3](https://bugzilla.suse.com/show_bug.cgi?id=CVE-2014-3495).