CVE-2012-1177
26.08.2012, 20:55
libgdata before 0.10.2 and 0.11.x before 0.11.1 does not validate SSL certificates, which allows remote attackers to obtain user names and passwords via a man-in-the-middle (MITM) attack with a spoofed certificate.Enginsight
| Vendor | Product | Version |
|---|---|---|
| gnome | libgdata | 𝑥 ≤ 0.10.1 |
| gnome | libgdata | 𝑥 ≤ 0.11.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| evolution-data-server |
| ||||||||||||
| libgdata |
|
Common Weakness Enumeration
References