CVE-2015-1337: Canonical Ubuntu Linux
Medium severity, CVSS 6.8. EPSS: 1.7% chance of exploitation in the next 30 days.
Simple Streams (simplestreams) does not properly verify the GPG signatures of disk image files, which allows remote mirror servers to spoof disk images and have unspecified other impact via a 403 (aka Forbidden) response.
Affected products
- Canonical Ubuntu Linux: version 14.04 only; version 15.04 only
- Simpestreams Project Simplestreams: affected versions not specified
Published 2015-10-09. Last modified 2026-06-17.