CVE-2021-39365
Summary
| CVE | CVE-2021-39365 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-08-22 22:15:00 UTC |
| Updated | 2021-12-16 20:36:00 UTC |
| Description | In GNOME grilo though 0.3.13, grl-net-wc.c does not enable TLS certificate verification on the SoupSessionAsync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Reminder: SoupSessionSync and SoupSessionAsync default to no TLS certificate verification – Michael Catanzaro's Blog |
MISC |
blogs.gnome.org |
|
| Debian -- Security Information -- DSA-4964-1 grilo |
DEBIAN |
www.debian.org |
|
| (CVE-2021-39365) Missing TLS certificate verification (#146) · Issues · GNOME / grilo · GitLab |
MISC |
gitlab.gnome.org |
|
| [SECURITY] [DLA 2762-1] grilo security update |
MLIST |
lists.debian.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159491 Oracle Enterprise Linux Security Update for grilo (ELSA-2021-4339)
- 178775 Debian Security Update for grilo (DSA 4964-1)
- 178802 Debian Security Update for grilo (DLA 2762-1)
- 181995 Debian Security Update for grilo (CVE-2021-39365)
- 198477 Ubuntu Security Notification for GNOME grilo Vulnerability (USN-5055-1)
- 239794 Red Hat Update for grilo (RHSA-2021:4339)
- 356432 Amazon Linux Security Advisory for grilo : ALAS2-2023-2306
- 671571 EulerOS Security Update for grilo (EulerOS-SA-2022-1567)
- 671599 EulerOS Security Update for grilo (EulerOS-SA-2022-1535)
- 751117 SUSE Enterprise Linux Security Update for grilo (SUSE-SU-2021:3003-1)
- 751174 OpenSUSE Security Update for grilo (openSUSE-SU-2021:3194-1)
- 751179 OpenSUSE Security Update for grilo (openSUSE-SU-2021:1312-1)
- 751193 SUSE Enterprise Linux Security Update for grilo (SUSE-SU-2021:3295-1)
- 940226 AlmaLinux Security Update for grilo (ALSA-2021:4339)
- 960238 Rocky Linux Security Update for grilo (RLSA-2021:4339)