Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1020 CNY

100%

CVE-2013-2100

EPSS 0.47% · P65
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2013-2100

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
The urlopen function in pym/portage/util/_urlopen.py in Gentoo Portage 2.1.12, when using HTTPS, does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and modify binary package lists via a crafted certificate.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Gentoo Portage‘urlopen()’加密问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Portage是Gentoo基金会的一款Gentoo Linux操作系统所使用的基于ports collection机制的包管理器。 Gentoo Portage 2.1.12版本的pym/portage/util/_urlopen.py文件中的‘urlopen’函数中存在安全漏洞,该漏洞源于程序使用HTTPS时,没有验证SSL服务器端的X.509证书。攻击者可通过特制的证书利用该漏洞实施中间人攻击,伪造数据欺骗服务器,修改二进制数据包列表。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2013-2100

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2013-2100

登录查看更多情报信息。

Same Patch Batch · n/a · 2014-09-29 · 53 CVEs total

CVE-2014-6789Android Anaheim Library 2Go!应用程序加密问题漏洞
CVE-2014-6804Android Investigation Tool应用程序加密问题漏洞
CVE-2014-6803Android Bank of Moscow EIRTS Rent应用程序加密问题漏洞
CVE-2014-6798Android McMaster Marauders应用程序加密问题漏洞
CVE-2014-6801Android frank matano应用程序加密问题漏洞
CVE-2014-6800Android Bloom Township 206应用程序加密问题漏洞
CVE-2014-6799Android Investigation Tool应用程序加密问题漏洞
CVE-2014-6802Android First Assembly NLR应用程序加密问题漏洞
CVE-2014-6791Android Angel Reigns应用程序加密问题漏洞
CVE-2014-6790Android INVEX应用程序加密问题漏洞
CVE-2014-6792Android Suriname Radio应用程序加密问题漏洞
CVE-2014-6788Android Oman News应用程序加密问题漏洞
CVE-2014-6787Android Counter Intuition应用程序加密问题漏洞
CVE-2014-6786Android Math for Kids - Subtraction应用程序加密问题漏洞
CVE-2014-6785Android Renny McLean Ministries应用程序加密问题漏洞
CVE-2014-6784Android Fermononrespiri Mobile应用程序加密问题漏洞
CVE-2014-6783Android Campus Link - Campus TV HKUSU应用程序加密问题漏洞
CVE-2014-6782Android Abraham Tours应用程序加密问题漏洞
CVE-2014-6781Android Aloha Stadium - Hawaii应用程序加密问题漏洞
CVE-2014-6780Android MeiTalk应用程序加密问题漏洞

Showing top 20 of 53 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2013-2100

No comments yet


Leave a comment