In GNOME libgda through 6.0.0, gda-web-provider.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.
The product does not validate, or incorrectly validates, a certificate.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Libgda | Gnome | * | 6.0.0 (including) |
Libgda5 | Ubuntu | bionic | * |
Libgda5 | Ubuntu | hirsute | * |
Libgda5 | Ubuntu | impish | * |
Libgda5 | Ubuntu | kinetic | * |
Libgda5 | Ubuntu | lunar | * |
Libgda5 | Ubuntu | mantic | * |
Libgda5 | Ubuntu | trusty | * |
Libgda5 | Ubuntu | xenial | * |