libgrss through 0.7.0 fails to perform TLS certificate verification when downloading feeds, allowing remote attackers to manipulate the contents of feeds without detection. This occurs because of the default behavior of SoupSessionSync.
References
Link | Resource |
---|---|
https://bugzilla.gnome.org/show_bug.cgi?id=772647 | Issue Tracking Vendor Advisory |
https://gitlab.gnome.org/GNOME/libgrss/-/issues/4 | Issue Tracking Vendor Advisory |
https://gitlab.gnome.org/GNOME/libgrss/-/merge_requests/7.patch | Mailing List Patch Vendor Advisory |
Configurations
Information
Published : 2021-05-25 14:15
Updated : 2021-06-09 08:03
NVD link : CVE-2016-20011
Mitre link : CVE-2016-20011
JSON object : View
CWE
CWE-295
Improper Certificate Validation
Products Affected
gnome
- libgrss