CVE-2021-39365

Name
CVE-2021-39365
Description
In GNOME grilo though 0.3.13, grl-net-wc.c does not enable TLS certificate verification on the SoupSessionAsync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://gitlab.gnome.org/GNOME/grilo/-/issues/146
MISC https://blogs.gnome.org/mcatanzaro/2021/05/25/reminder-soupsessionsync-and-soupsessionasync-default-to-no-tls-certificate-verification/
DEBIAN https://www.debian.org/security/2021/dsa-4964

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:gnome:grilo:*:*:*:*:*:*:*:* grilo >= None <= 0.3.13

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
grilo 3.14-community 0.3.13-r1 Rasmus Thomsen <oss@cogitri.dev> possibly vulnerable