MGASA-2021-0530

Source
https://advisories.mageia.org/MGASA-2021-0530.html
Import Source
https://advisories.mageia.org/MGASA-2021-0530.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2021-0530
Related
Published
2021-12-02T16:49:28Z
Modified
2021-12-02T16:15:09Z
Summary
Updated gfbgraph packages fix security vulnerability
Details

In GNOME libgfbgraph through 0.2.4, gfbgraph-photo.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.

References
Credits

Affected packages

Mageia:8 / gfbgraph

Package

Name
gfbgraph
Purl
pkg:rpm/mageia/gfbgraph?distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.2.4-1.1.mga8

Ecosystem specific

{
    "section": "core"
}