PT-2021-22568 · Gnome+8 · Gnome Grilo+8

·

CVE-2021-39365

·

Published

2021-08-22

·

Updated

2022-09-01

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: GNOME grilo versions prior to 0.3.14
Description: The issue is related to the lack of TLS certificate verification in the SoupSessionAsync objects created by grl-net-wc.c, making users susceptible to network man-in-the-middle (MITM) attacks.
Recommendations: For versions prior to 0.3.14, update to version 0.3.14 or later to enable TLS certificate verification and prevent MITM attacks.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2021:4339
ALT-PU-2021-2976
ALT-PU-2022-2539
CESA-2021_4339
CVE-2021-39365
DLA-2762-1
DSA-4964-1
MGASA-2021-0472
OESA-2021-1346
OPENSUSE-SU-2021:1312-1
OPENSUSE-SU-2021:3194-1
OPENSUSE-SU-2021_1312-1
OPENSUSE-SU-2021_3194-1
OPENSUSE-SU-2024:10822-1
RHSA-2021:4339
RHSA-2021_4339
RLSA-2021:4339
SUSE-SU-2021:3003-1
SUSE-SU-2021:3194-1
SUSE-SU-2021:3295-1
SUSE-SU-2021_3003-1
SUSE-SU-2021_3194-1
SUSE-SU-2021_3295-1
USN-5055-1

Affected Products

Alt Linux
Almalinux
Centos
Gnome Grilo
Linuxmint
Red Hat
Rocky Linux
Suse
Ubuntu