Candidate: CVE-2015-3886 PublicDate: 2017-07-21 14:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3886 http://www.openwall.com/lists/oss-security/2015/05/12/1 Description: libinfinity before 0.6.6-1 does not validate expired SSL certificates, which allows remote attackers to have unspecified impact via unknown vectors. Ubuntu-Description: Notes: Bugs: https://github.com/gobby/gobby/issues/61 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=783601 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL] Patches_libinfinity: upstream: https://github.com/gobby/libinfinity/commit/c97f870f5ae13112988d9f8ad464b4f679903706 upstream_libinfinity: released (0.6.6-1) precise_libinfinity: ignored (reached end-of-life) precise/esm_libinfinity: DNE (precise was needs-triage) trusty_libinfinity: not-affected (code not present) trusty/esm_libinfinity: DNE (trusty was not-affected [code not present]) utopic_libinfinity: ignored (reached end-of-life) vivid_libinfinity: ignored (reached end-of-life) vivid/stable-phone-overlay_libinfinity: DNE vivid/ubuntu-core_libinfinity: DNE wily_libinfinity: not-affected (0.6.6-1) xenial_libinfinity: not-affected (0.6.6-1) yakkety_libinfinity: not-affected (0.6.6-1) zesty_libinfinity: not-affected (0.6.6-1) artful_libinfinity: not-affected (0.6.6-1) bionic_libinfinity: not-affected (0.6.6-1) cosmic_libinfinity: not-affected (0.6.6-1) devel_libinfinity: not-affected (0.6.6-1)