Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2012-1177

Overview

Vulnerability Score 5.1 5.1
CVE Id CVE-2012-1177
Last Modified 04 Apr 2013 11:09:06
Published 26 Aug 2012 04:55:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity HIGH
Authentication NONE

CVE-2012-1177

Summary

libgdata before 0.10.2 and 0.11.x before 0.11.1 does not validate SSL certificates, which allows remote attackers to obtain user names and passwords via a man-in-the-middle (MITM) attack with a spoofed certificate.

Vulnerable Systems

Application

  • Gnome Libgdata 0.10.1

  • Gnome Libgdata 0.11.0


References

MISC - https://bugzilla.novell.com/show_bug.cgi?id=752088

MISC - https://bugzilla.gnome.org/show_bug.cgi?id=671535

MISC - https://bugs.launchpad.net/ubuntu/+source/libgdata/+bug/938812

MLIST - [oss-security] 20120314 Re: CVE Request: libgdata did not verify SSL certificates

MLIST - [oss-security] 20120314 CVE Request: libgdata did not verify SSL certificates

CONFIRM - http://git.gnome.org/browse/libgdata/commit/?id=6799f2c525a584dc998821a6ce897e463dad7840

CONFIRM - http://git.gnome.org/browse/libgdata/commit/?h=libgdata-0-10&id=8eff8fa9138859e03e58c2aa76600ab63eb5c29c

UBUNTU - USN-1547-1

DEBIAN - DSA-2482

SECUNIA - 50432

MANDRIVA - MDVSA-2012:111


Last Updated: 27 May 2016 11:00:18