PT-2012-3827 · Gnome+2 · Libsoup+2

Michael Vogt

·

Published

2012-07-12

·

Updated

2017-08-29

·

CVE-2012-2132

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions libsoup versions 2.32.2 and earlier
Description The issue allows remote attackers to bypass authentication by connecting with an SSL connection, as it does not validate certificates or clear the trust flag when the ssl-ca-file does not exist.
Recommendations For versions 2.32.2 and earlier, ensure the ssl-ca-file exists and is properly configured to validate certificates and maintain the trust flag. As a temporary workaround, consider disabling SSL connections until a proper fix is applied.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-2132
SUSE-SU-2012_0870-1

Affected Products

Debian
Suse
Libsoup