PT-2012-3827 · Gnome+2 · Libsoup+2

Michael Vogt

·

Publicado

2012-07-12

·

Atualizado

2017-08-29

·

CVE-2012-2132

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions libsoup versions 2.32.2 and earlier
Description The issue allows remote attackers to bypass authentication by connecting with an SSL connection, as it does not validate certificates or clear the trust flag when the ssl-ca-file does not exist.
Recommendations For versions 2.32.2 and earlier, ensure the ssl-ca-file exists and is properly configured to validate certificates and maintain the trust flag. As a temporary workaround, consider disabling SSL connections until a proper fix is applied.

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2012-2132
SUSE-SU-2012_0870-1

Produtos afetados

Debian
Suse
Libsoup