Candidate: CVE-2013-2073 PublicDate: 2014-05-02 01:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2073 http://seclists.org/oss-sec/2013/q2/394 Description: Transifex command-line client before 0.9 does not validate X.509 certificates, which allows man-in-the-middle attackers to spoof a Transifex server via an arbitrary certificate. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Florian Weimer Assigned-to: CVSS: Patches_transifex-client: upstream: https://github.com/transifex/transifex-client/commit/e24ea954373874962f22f63a7311d04d6ff56d84 (p1) upstream: https://github.com/transifex/transifex-client/commit/f237dd7d3f4f08be7160f32eb99edafe2769aad1 (p2) upstream: https://github.com/transifex/transifex-client/commit/5246f188b0abcc1a4c20894fcab88f7a6cd6cfd9 (p3) upstream: https://github.com/transifex/transifex-client/commit/ad29a9dbe869e0c7d861826a82c9ce2f022face4 (p4) upstream_transifex-client: released (0.9-1) lucid_transifex-client: DNE precise_transifex-client: ignored (reached end-of-life) precise/esm_transifex-client: DNE (precise was needed) quantal_transifex-client: ignored (reached end-of-life) raring_transifex-client: ignored (reached end-of-life) saucy_transifex-client: not-affected (0.9.1-1) trusty_transifex-client: not-affected (0.10-1) trusty/esm_transifex-client: DNE (trusty was not-affected [0.10-1]) utopic_transifex-client: not-affected (0.10-1) vivid_transifex-client: not-affected (0.10-1) vivid/stable-phone-overlay_transifex-client: DNE vivid/ubuntu-core_transifex-client: DNE wily_transifex-client: not-affected (0.10-1) xenial_transifex-client: not-affected (0.10-1) yakkety_transifex-client: not-affected (0.10-1) zesty_transifex-client: not-affected (0.10-1) devel_transifex-client: not-affected (0.10-1)