CVE-2013-1799
02.04.2013, 03:23
Gnome Online Accounts (GOA) 3.6.x before 3.6.3 and 3.7.x before 3.7.91, does not properly validate SSL certificates when creating accounts for providers who use the libsoup library, which allows man-in-the-middle attackers to obtain sensitive information such as credentials by sniffing the network. NOTE: this issue exists because of an incomplete fix for CVE-2013-0240.Enginsight
| Vendor | Product | Version |
|---|---|---|
| gnome | gnome_online_accounts | 3.6.0 |
| gnome | gnome_online_accounts | 3.6.1 |
| gnome | gnome_online_accounts | 3.6.2 |
| gnome | gnome_online_accounts | 3.7.1 |
| gnome | gnome_online_accounts | 3.7.2 |
| gnome | gnome_online_accounts | 3.7.3 |
| gnome | gnome_online_accounts | 3.7.4 |
| gnome | gnome_online_accounts | 3.7.90 |
| canonical | ubuntu_linux | 11.10 |
| canonical | ubuntu_linux | 12.04 |
| canonical | ubuntu_linux | 12.10 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
References