UBUNTU-CVE-2021-3618
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-3618
UBUNTU-CVE-2021-3618
Summary:
Details: ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A MiTM attacker having access to victim's traffic at the TCP/IP layer can redirect traffic from one subdomain to another, resulting in a valid TLS session. This breaks the authentication of TLS and cross-protocol attacks may be possible where the behavior of one protocol service may compromise the other at the application layer.
References: https://ubuntu.com/security/CVE-2021-3618, https://security.appspot.com/vsftpd/Changelog.txt, https://alpaca-attack.com/, https://marc.info/?l=sendmail-announce&m=159394546814125&w=2, https://lists.exim.org/lurker/message/20210609.200324.f0e073ed.el.html, https://ubuntu.com/security/notices/USN-5371-1, https://ubuntu.com/security/notices/USN-5371-2, https://ubuntu.com/security/notices/USN-6379-1, https://www.cve.org/CVERecord?id=CVE-2021-3618
Affected packages
Package
Name: nginx
Purl: pkg:deb/ubuntu/nginx?arch=source&distro=esm-infra-legacy%2Ftrusty
Affected ranges
Type: ECOSYSTEM
Events:
