{"id":"CVE-2011-3634","details":"methods/https.cc in apt before 0.8.11 accepts connections when the certificate host name fails validation and Verify-Host is enabled, which allows man-in-the-middle attackers to obtain repository credentials via unspecified vectors.","modified":"2026-04-10T03:41:59.801736Z","published":"2014-03-01T00:55:04Z","references":[{"type":"ADVISORY","url":"http://www.ubuntu.com/usn/USN-1283-1"},{"type":"WEB","url":"http://people.canonical.com/~ubuntu-security/cve/2011/CVE-2011-3634.html"},{"type":"WEB","url":"https://alioth.debian.org/plugins/scmgit/cgi-bin/gitweb.cgi?p=apt/apt.git%3Ba=blob%3Bf=debian/changelog%3Bhb=HEAD"},{"type":"WEB","url":"https://bugs.launchpad.net/ubuntu/+source/apt/+bug/868353"}],"schema_version":"1.7.5"}