CVE-2016-20011
Summary
| CVE | CVE-2016-20011 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-05-25 21:15:00 UTC |
| Updated | 2021-06-09 15:03:00 UTC |
| Description | libgrss through 0.7.0 fails to perform TLS certificate verification when downloading feeds, allowing remote attackers to manipulate the contents of feeds without detection. This occurs because of the default behavior of SoupSessionSync. |
Risk And Classification
Problem Types: CWE-295
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Bug 772647 – Perform TLS certificate verification | MISC | bugzilla.gnome.org | |
| (CVE-2016-20011) No TLS certificate verification (#4) · Issues · GNOME / libgrss · GitLab | MISC | gitlab.gnome.org | |
| gitlab.gnome.org/GNOME/libgrss/-/merge_requests/7.patch | MISC | gitlab.gnome.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 501604 Alpine Linux Security Update for libgrss