CVE Vulnerabilities

CVE-2016-20011

Improper Certificate Validation

Published: May 25, 2021 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

libgrss through 0.7.0 fails to perform TLS certificate verification when downloading feeds, allowing remote attackers to manipulate the contents of feeds without detection. This occurs because of the default behavior of SoupSessionSync.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

NameVendorStart VersionEnd Version
LibgrssGnome*0.7.0 (including)
LibgrssUbuntubionic*
LibgrssUbuntufocal*
LibgrssUbuntugroovy*
LibgrssUbuntuhirsute*
LibgrssUbuntuimpish*
LibgrssUbuntukinetic*
LibgrssUbuntulunar*
LibgrssUbuntumantic*
LibgrssUbuntutrusty*
LibgrssUbuntuxenial*

Potential Mitigations

References