Vulnerability CVE-2021-39358: Information

Description

In GNOME libgfbgraph through 0.2.4, gfbgraph-photo.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.

Severity: MEDIUM (5.9) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Published: Aug. 22, 2021
Modified: Nov. 7, 2023
Error type identifier: CWE-295

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
libgfbgraphsisyphus0.2.5-alt10.2.5-alt1ALT-PU-2021-3165-1288578Fixed
libgfbgraphsisyphus_e2k0.2.5-alt10.2.5-alt1ALT-PU-2021-4549-1-Fixed
libgfbgraphp100.2.5-alt10.2.5-alt1ALT-PU-2021-3500-1289899Fixed
libgfbgraphc10f10.2.5-alt10.2.5-alt1ALT-PU-2021-3500-1289899Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:gnome:libgfbgraph:*:*:*:*:*:*:*:*
      End including
      0.2.4

      Configuration 2

      cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*

      cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*

      cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*