libgrss through 0.7.0 fails to perform TLS certificate verification when downloading feeds, allowing remote attackers to manipulate the contents of feeds without detection. This occurs because of the default behavior of SoupSessionSync.
References
| Link | Resource |
|---|---|
| https://bugzilla.gnome.org/show_bug.cgi?id=772647 | Issue Tracking Vendor Advisory |
| https://gitlab.gnome.org/GNOME/libgrss/-/issues/4 | Issue Tracking Vendor Advisory |
| https://gitlab.gnome.org/GNOME/libgrss/-/merge_requests/7.patch | Mailing List Patch Vendor Advisory |
Configurations
Information
Published : 2021-05-25 14:15
Updated : 2021-06-09 08:03
NVD link : CVE-2016-20011
Mitre link : CVE-2016-20011
JSON object : View
CWE
CWE-295
Improper Certificate Validation
Products Affected
gnome
- libgrss


