4.3
CVE-2013-1799
- EPSS 0.56%
- Published 02.04.2013 03:23:26
- Last modified 11.04.2025 00:51:21
- Source secalert@redhat.com
- Teams watchlist Login
- Open Login
Gnome Online Accounts (GOA) 3.6.x before 3.6.3 and 3.7.x before 3.7.91, does not properly validate SSL certificates when creating accounts for providers who use the libsoup library, which allows man-in-the-middle attackers to obtain sensitive information such as credentials by sniffing the network. NOTE: this issue exists because of an incomplete fix for CVE-2013-0240.
Data is provided by the National Vulnerability Database (NVD)
Gnome ≫ Gnome Online Accounts Version3.6.0
Gnome ≫ Gnome Online Accounts Version3.6.1
Gnome ≫ Gnome Online Accounts Version3.6.2
Gnome ≫ Gnome Online Accounts Version3.7.1
Gnome ≫ Gnome Online Accounts Version3.7.2
Gnome ≫ Gnome Online Accounts Version3.7.3
Gnome ≫ Gnome Online Accounts Version3.7.4
Gnome ≫ Gnome Online Accounts Version3.7.90
Canonical ≫ Ubuntu Linux Version11.10
Canonical ≫ Ubuntu Linux Version12.04 Update- Editionlts
Canonical ≫ Ubuntu Linux Version12.10
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.56% | 0.654 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:P/I:N/A:N
|