CVE-2010-3900
EPSS 1.2%
描述
Midori before 0.2.5, when WebKitGTK+ before 1.1.14 or LibSoup before 2.29.91 is used, does not verify X.509 certificates, which allows man-in-the-middle attackers to spoof arbitrary https web sites via a crafted server certificate, a related issue to CVE-2010-3312.
如何修補 CVE-2010-3900
要修補 CVE-2010-3900,請將受影響套件升級到下列已修補版本。
- Debian/midori—升級至 0.2.7-1.1 或更新版本
CVE-2010-3900 正在被利用嗎?
低 — EPSS 為 1.2%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 0.2.7-1.1