Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2021-4339

Опубликовано: 16 нояб. 2021
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2021-4339: grilo security update (MODERATE)

[0.3.6-3]

  • grilo-0.3.6-3
  • Fix TLS not being validated correctly
  • Resolves: rhbz#1997234

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

grilo

0.3.6-3.el8

grilo-devel

0.3.6-3.el8

Oracle Linux x86_64

grilo

0.3.6-3.el8

grilo-devel

0.3.6-3.el8

Связанные CVE

Связанные уязвимости

CVSS3: 5.9
ubuntu
почти 4 года назад

In GNOME grilo though 0.3.13, grl-net-wc.c does not enable TLS certificate verification on the SoupSessionAsync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.

CVSS3: 7.5
redhat
около 4 лет назад

In GNOME grilo though 0.3.13, grl-net-wc.c does not enable TLS certificate verification on the SoupSessionAsync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.

CVSS3: 5.9
nvd
почти 4 года назад

In GNOME grilo though 0.3.13, grl-net-wc.c does not enable TLS certificate verification on the SoupSessionAsync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.

CVSS3: 5.9
debian
почти 4 года назад

In GNOME grilo though 0.3.13, grl-net-wc.c does not enable TLS certifi ...

suse-cvrf
почти 4 года назад

Security update for grilo