PT-2021-22568 · Gnome+8 · Gnome Grilo+8

Michael Catanzaro

·

Published

2021-08-22

·

Updated

2022-09-01

·

CVE-2021-39365

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: GNOME grilo versions prior to 0.3.14
Description: The issue is related to the lack of TLS certificate verification in the SoupSessionAsync objects created by grl-net-wc.c, making users susceptible to network man-in-the-middle (MITM) attacks.
Recommendations: For versions prior to 0.3.14, update to version 0.3.14 or later to enable TLS certificate verification and prevent MITM attacks.

Fix

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

ALSA-2021:4339
ALT-PU-2021-2976
ALT-PU-2022-2539
CESA-2021_4339
CVE-2021-39365
DLA-2762-1
DSA-4964-1
MGASA-2021-0472
OESA-2021-1346
OPENSUSE-SU-2021:1312-1
OPENSUSE-SU-2021:3194-1
OPENSUSE-SU-2021_1312-1
OPENSUSE-SU-2021_3194-1
OPENSUSE-SU-2024:10822-1
RHSA-2021:4339
RHSA-2021_4339
RLSA-2021:4339
SUSE-SU-2021:3003-1
SUSE-SU-2021:3194-1
SUSE-SU-2021:3295-1
SUSE-SU-2021_3003-1
SUSE-SU-2021_3194-1
SUSE-SU-2021_3295-1
USN-5055-1

Affected Products

Alt Linux
Almalinux
Centos
Gnome Grilo
Linuxmint
Red Hat
Rocky Linux
Suse
Ubuntu