1 results (0.005 seconds)

CVSS: 7.4EPSS: 0%CPEs: 11EXPL: 0

28 Mar 2013 — Gnome Online Accounts (GOA) 3.6.x before 3.6.3 and 3.7.x before 3.7.91, does not properly validate SSL certificates when creating accounts for providers who use the libsoup library, which allows man-in-the-middle attackers to obtain sensitive information such as credentials by sniffing the network. NOTE: this issue exists because of an incomplete fix for CVE-2013-0240. Gnome Online Accounts (GOA) 3.6.x anterior a 3.6.3 y 3.7.x anterior a 3.7.91, no valida adecuadamente los certificados SSL cuando crear cuen... • http://lists.opensuse.org/opensuse-updates/2013-02/msg00046.html • CWE-310: Cryptographic Issues •