CVE-2015-1337

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
09/10/2015
Last modified:
12/04/2025

Description

Simple Streams (simplestreams) does not properly verify the GPG signatures of disk image files, which allows remote mirror servers to spoof disk images and have unspecified other impact via a 403 (aka Forbidden) response.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:simpestreams_project:simplestreams:-:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:15.04:*:*:*:*:*:*:*