CVE-2015-1337

Description

Simple Streams (simplestreams) does not properly verify the GPG signatures of disk image files, which allows remote mirror servers to spoof disk images and have unspecified other impact via a 403 (aka Forbidden) response.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.334

Associated Vulnerability

VulnerabilityOS Platform
Library and tools for using Simple Streams data (USN-2746-1) simplestreams_0.1.0~bzr341-0ubuntu2.3_all.debLinux
Library and tools for using Simple Streams data (USN-2746-1) python-simplestreams_0.1.0~bzr341-0ubuntu2.3_all.debLinux
Library and tools for using Simple Streams data (USN-2746-1) python3-simplestreams_0.1.0~bzr341-0ubuntu2.3_all.debLinux
Library and tools for using Simple Streams data (USN-2746-1) python-simplestreams-openstack_0.1.0~bzr341-0ubuntu2.3_all.debLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234