5.1
CVSSv2

CVE-2012-1177

Published: 26/08/2012 Updated: 05/04/2013
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
VMScore: 454
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

libgdata prior to 0.10.2 and 0.11.x prior to 0.11.1 does not validate SSL certificates, which allows remote malicious users to obtain user names and passwords via a man-in-the-middle (MITM) attack with a spoofed certificate.

Vulnerable Product Search on Vulmon Subscribe to Product

gnome libgdata

Vendor Advisories

Debian Bug report logs - #664032 [CVE-2012-1177] libgdata do not verify SSL certs Package: libgdata; Maintainer for libgdata is Debian GNOME Maintainers <pkg-gnome-maintainers@listsaliothdebianorg>; Reported by: Luciano Bello <luciano@debianorg> Date: Wed, 14 Mar 2012 23:21:01 UTC Severity: grave Tags: patch, sec ...
Applications using GData services could be made to expose sensitive information over the network ...
Vreixo Formoso discovered that libgdata, a library used to access various Google services, wasn't validating certificates against trusted system root CAs when using an HTTPS connection For the stable distribution (squeeze), this problem has been fixed in version 064-2+squeeze1 For the testing distribution (wheezy), this problem has been fixed i ...