7.5
CVSSv3

CVE-2014-3495

Published: 13/12/2019 Updated: 19/12/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

duplicity 0.6.24 has improper verification of SSL certificates

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

debian duplicity 0.6.24

debian debian linux 8.0

debian debian linux 9.0

debian debian linux 10.0

opensuse opensuse 12.3

opensuse opensuse 13.1

Vendor Advisories

Debian Bug report logs - #751902 duplicity should enable boto's certificate verification option (CVE-2014-3495) Package: duplicity; Maintainer for duplicity is Alexander Zangerl <az@debianorg>; Source for duplicity is src:duplicity (PTS, buildd, popcon) Reported by: Henri Salo <henri@nervfi> Date: Tue, 17 Jun 2014 ...