libsoup 2.32.2 and earlier does not validate certificates or clear the trust flag when the ssl-ca-file does not exist, which allows remote attackers to bypass authentication by connecting with a SSL connection.
References
Configurations
Information
Published : 2012-08-20 11:55
Updated : 2017-08-28 18:31
NVD link : CVE-2012-2132
Mitre link : CVE-2012-2132
JSON object : View
CWE
CWE-287
Improper Authentication
Products Affected
gnome
- libsoup