CVE-2013-0240
Summary
| CVE | CVE-2013-0240 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-04-02 03:22:21 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Gnome Online Accounts (GOA) 3.4.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.5, does not properly validate SSL certificates when creating accounts such as Windows Live and Facebook accounts, which allows man-in-the-middle attackers to obtain sensitive information such as credentials by sniffing the network. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:M/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Canonical | Ubuntu Linux | 11.10 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 12.04 | - | lts | All |
| Operating System | Canonical | Ubuntu Linux | 12.10 | All | All | All |
| Application | Gnome | Gnome Online Accounts | 3.4.0 | All | All | All |
| Application | Gnome | Gnome Online Accounts | 3.4.1 | All | All | All |
| Application | Gnome | Gnome Online Accounts | 3.6.0 | All | All | All |
| Application | Gnome | Gnome Online Accounts | 3.6.1 | All | All | All |
| Application | Gnome | Gnome Online Accounts | 3.6.2 | All | All | All |
| Application | Gnome | Gnome Online Accounts | 3.7.1 | All | All | All |
| Application | Gnome | Gnome Online Accounts | 3.7.2 | All | All | All |
| Application | Gnome | Gnome Online Accounts | 3.7.3 | All | All | All |
| Application | Gnome | Gnome Online Accounts | 3.7.4 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Prepare 3.7.5 (bc10fdb6) · Commits · GNOME / gnome-online-accounts · GitLab | af854a3a-2127-422b-91ae-364da2661108 | git.gnome.org | |
| openSUSE-SU-2013:0301-1: moderate: gnome-online-accounts: enable ssl cer | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Guard against invalid SSL certificates (ecad8142) · Commits · GNOME / gnome-online-accounts · GitLab | af854a3a-2127-422b-91ae-364da2661108 | git.gnome.org | |
| 894352 – (CVE-2013-0240, CVE-2013-1799) CVE-2013-0240 gnome-online-accounts: Does not check SSL certificates when creating Windows Live or Facebook accounts | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| Security Advisory SA51976 - GNOME Online Accounts SSL Certificate Verification Security Issue - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| USN-1779-1: GNOME Online Accounts vulnerability | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | ubuntu.com | |
| Bug 693214 – CVE-2013-0240: fails to verify SSL certificates when creating accounts | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.gnome.org | |
| GNOME Online Accounts 3.6.3 released | af854a3a-2127-422b-91ae-364da2661108 | mail.gnome.org | |
| Security Advisory SA52791 - Ubuntu update for gnome-online-accounts - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Guard against invalid SSL certificates (edde7c63) · Commits · GNOME / gnome-online-accounts · GitLab | af854a3a-2127-422b-91ae-364da2661108 | git.gnome.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.