6.8
CVSSv2

CVE-2015-1337

Published: 09/10/2015 Updated: 09/10/2015
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Simple Streams (simplestreams) does not properly verify the GPG signatures of disk image files, which allows remote mirror servers to spoof disk images and have unspecified other impact via a 403 (aka Forbidden) response.

Vulnerable Product Search on Vulmon Subscribe to Product

simpestreams project simplestreams -

canonical ubuntu linux 15.04

canonical ubuntu linux 14.04

Vendor Advisories

Applications using Simple Streams could be made to crash or run programs if it received specially crafted network traffic ...