4.3

CVE-2013-1799

Gnome Online Accounts (GOA) 3.6.x before 3.6.3 and 3.7.x before 3.7.91, does not properly validate SSL certificates when creating accounts for providers who use the libsoup library, which allows man-in-the-middle attackers to obtain sensitive information such as credentials by sniffing the network.  NOTE: this issue exists because of an incomplete fix for CVE-2013-0240.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GnomeGnome Online Accounts Version3.6.0
GnomeGnome Online Accounts Version3.6.1
GnomeGnome Online Accounts Version3.6.2
GnomeGnome Online Accounts Version3.7.1
GnomeGnome Online Accounts Version3.7.2
GnomeGnome Online Accounts Version3.7.3
GnomeGnome Online Accounts Version3.7.4
GnomeGnome Online Accounts Version3.7.90
CanonicalUbuntu Linux Version11.10
CanonicalUbuntu Linux Version12.04 Update- Editionlts
CanonicalUbuntu Linux Version12.10
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.56% 0.654
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N