Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-6750

Опубликовано: 09 янв. 2020
Источник: redhat
CVSS3: 6.8

Описание

GSocketClient in GNOME GLib through 2.62.4 may occasionally connect directly to a target address instead of connecting via a proxy server when configured to do so, because the proxy_addr field is mishandled. This bug is timing-dependent and may occur only sporadically depending on network delays. The greatest security relevance is in use cases where a proxy is used to help with privacy/anonymity, even though there is no technical barrier to a direct connection. NOTE: versions before 2.60 are unaffected.

Отчет

As per upstream versions of glib2 before 2.60 are unaffected, therefore glib2 package shipped with Red Hat Products are not affected by this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5glibNot affected
Red Hat Enterprise Linux 5glib2Not affected
Red Hat Enterprise Linux 6chromium-browserNot affected
Red Hat Enterprise Linux 6firefoxNot affected
Red Hat Enterprise Linux 6glib2Not affected
Red Hat Enterprise Linux 6thunderbirdNot affected
Red Hat Enterprise Linux 7glib2Not affected
Red Hat Enterprise Linux 8glib2Not affected
Red Hat Enterprise Linux 8mingw-glib2Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1790288glib: Mishandling of proxy_addr field in GSocketClient may lead to proxy being ignored

6.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
около 6 лет назад

GSocketClient in GNOME GLib through 2.62.4 may occasionally connect directly to a target address instead of connecting via a proxy server when configured to do so, because the proxy_addr field is mishandled. This bug is timing-dependent and may occur only sporadically depending on network delays. The greatest security relevance is in use cases where a proxy is used to help with privacy/anonymity, even though there is no technical barrier to a direct connection. NOTE: versions before 2.60 are unaffected.

CVSS3: 5.9
nvd
около 6 лет назад

GSocketClient in GNOME GLib through 2.62.4 may occasionally connect directly to a target address instead of connecting via a proxy server when configured to do so, because the proxy_addr field is mishandled. This bug is timing-dependent and may occur only sporadically depending on network delays. The greatest security relevance is in use cases where a proxy is used to help with privacy/anonymity, even though there is no technical barrier to a direct connection. NOTE: versions before 2.60 are unaffected.

CVSS3: 5.9
msrc
около 4 лет назад

Описание отсутствует

CVSS3: 5.9
debian
около 6 лет назад

GSocketClient in GNOME GLib through 2.62.4 may occasionally connect di ...

github
больше 3 лет назад

GSocketClient in GNOME GLib through 2.62.4 may occasionally connect directly to a target address instead of connecting via a proxy server when configured to do so, because the proxy_addr field is mishandled. This bug is timing-dependent and may occur only sporadically depending on network delays. The greatest security relevance is in use cases where a proxy is used to help with privacy/anonymity, even though there is no technical barrier to a direct connection. NOTE: versions before 2.60 are unaffected.

6.8 Medium

CVSS3