Grilo is a framework focused on making media discovery and browsing easy for application developers.
Security Fix(es):
In GNOME grilo though 0.3.13, grl-net-wc.c does not enable TLS certificate verification on the SoupSessionAsync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.(CVE-2021-39365)
{ "severity": "Medium" }
{ "src": [ "grilo-0.3.9-4.oe1.src.rpm" ], "x86_64": [ "grilo-debugsource-0.3.9-4.oe1.x86_64.rpm", "grilo-devel-0.3.9-4.oe1.x86_64.rpm", "grilo-0.3.9-4.oe1.x86_64.rpm", "grilo-debuginfo-0.3.9-4.oe1.x86_64.rpm" ], "noarch": [ "grilo-help-0.3.9-4.oe1.noarch.rpm" ], "aarch64": [ "grilo-devel-0.3.9-4.oe1.aarch64.rpm", "grilo-debugsource-0.3.9-4.oe1.aarch64.rpm", "grilo-0.3.9-4.oe1.aarch64.rpm", "grilo-debuginfo-0.3.9-4.oe1.aarch64.rpm" ] }
{ "src": [ "grilo-0.3.9-4.oe1.src.rpm" ], "x86_64": [ "grilo-devel-0.3.9-4.oe1.x86_64.rpm", "grilo-debugsource-0.3.9-4.oe1.x86_64.rpm", "grilo-0.3.9-4.oe1.x86_64.rpm", "grilo-debuginfo-0.3.9-4.oe1.x86_64.rpm" ], "noarch": [ "grilo-help-0.3.9-4.oe1.noarch.rpm" ], "aarch64": [ "grilo-debuginfo-0.3.9-4.oe1.aarch64.rpm", "grilo-devel-0.3.9-4.oe1.aarch64.rpm", "grilo-0.3.9-4.oe1.aarch64.rpm", "grilo-debugsource-0.3.9-4.oe1.aarch64.rpm" ] }