6.5
CVE-2020-13645
- EPSS 1.97%
- Veröffentlicht 28.05.2020 12:15:11
- Zuletzt bearbeitet 21.11.2024 05:01:40
- Erkennungen
In GNOME glib-networking through 2.64.2, the implementation of GTlsClientConnection skips hostname verification of the server's TLS certificate if the application fails to specify the expected server identity. This is in contrast to its intended documented behavior, to fail the certificate verification. Applications that fail to provide the server identity, including Balsa before 2.5.11 and 2.6.x before 2.6.1, accept a TLS certificate if the certificate is valid for any host.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Gnome ≫ Glib-networking Version < 2.62.4
Gnome ≫ Glib-networking Version >= 2.64.0 < 2.64.3
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 19.10
Canonical ≫ Ubuntu Linux Version 20.04 SwEdition lts
Fedoraproject ≫ Fedora Version 31
Fedoraproject ≫ Fedora Version 32
Netapp ≫ Cloud Backup Version -
Broadcom ≫ Fabric Operating System Version -
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.97% | 0.787 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.5 | 3.9 | 2.5 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
|
| NIST | 6.4 | 10 | 4.9 |
AV:N/AC:L/Au:N/C:P/I:P/A:N
|
CWE-295 Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.
https://gitlab.gnome.org/GNOME/balsa/-/issues/34
https://gitlab.gnome.org/GNOME/glib-networking/-/issues/135
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HLEX2IP62SU6WJ4SK3U766XGLQK3J62O/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LRCUM22YEWWKNMN2BP5LTVDM5P4VWIXS/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TQEQJQ4XFMFCFJTEXKL2ZO3UELBPCKSK/
https://security.gentoo.org/glsa/202007-50
https://security.netapp.com/advisory/ntap-20200608-0004/
https://usn.ubuntu.com/4405-1/