Gnome Online Accounts (GOA) 3.6.x before 3.6.3 and 3.7.x before 3.7.91, does not properly validate SSL certificates when creating accounts for providers who use the libsoup library, which allows man-in-the-middle attackers to obtain sensitive information such as credentials by sniffing the network. NOTE: this issue exists because of an incomplete fix for CVE-2013-0240.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
History
21 Nov 2024, 01:50
Type | Values Removed | Values Added |
---|---|---|
References | () http://lists.opensuse.org/opensuse-updates/2013-02/msg00046.html - | |
References | () http://secunia.com/advisories/51976 - Vendor Advisory | |
References | () http://secunia.com/advisories/52791 - Vendor Advisory | |
References | () http://ubuntu.com/usn/usn-1779-1 - | |
References | () https://bugzilla.gnome.org/show_bug.cgi?id=693214 - | |
References | () https://bugzilla.gnome.org/show_bug.cgi?id=695106 - | |
References | () https://git.gnome.org/browse/gnome-online-accounts/commit/?id=9cf4bc0ced2c53bcdd36922caa65afc8a167bbd8 - | |
References | () https://mail.gnome.org/archives/gnome-announce-list/2013-March/msg00007.html - | |
References | () https://mail.gnome.org/archives/gnome-announce-list/2013-March/msg00020.html - |
07 Nov 2023, 02:14
Type | Values Removed | Values Added |
---|---|---|
Summary | Gnome Online Accounts (GOA) 3.6.x before 3.6.3 and 3.7.x before 3.7.91, does not properly validate SSL certificates when creating accounts for providers who use the libsoup library, which allows man-in-the-middle attackers to obtain sensitive information such as credentials by sniffing the network. NOTE: this issue exists because of an incomplete fix for CVE-2013-0240. |
Information
Published : 2013-04-02 03:23
Updated : 2024-11-21 01:50
NVD link : CVE-2013-1799
Mitre link : CVE-2013-1799
CVE.ORG link : CVE-2013-1799
JSON object : View
Products Affected
gnome
- gnome_online_accounts
canonical
- ubuntu_linux
CWE
CWE-310
Cryptographic Issues