4.3
CVSSv2

CVE-2013-0240

Published: 02/04/2013 Updated: 02/04/2013
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

Gnome Online Accounts (GOA) 3.4.x, 3.6.x prior to 3.6.3, and 3.7.x prior to 3.7.5, does not properly validate SSL certificates when creating accounts such as Windows Live and Facebook accounts, which allows man-in-the-middle malicious users to obtain sensitive information such as credentials by sniffing the network.

Vulnerable Product Search on Vulmon Subscribe to Product

gnome gnome online accounts 3.4.0

gnome gnome online accounts 3.4.1

gnome gnome online accounts 3.6.0

gnome gnome online accounts 3.6.1

gnome gnome online accounts 3.6.2

gnome gnome online accounts 3.7.1

gnome gnome online accounts 3.7.3

gnome gnome online accounts 3.7.2

gnome gnome online accounts 3.7.4

canonical ubuntu linux 11.10

canonical ubuntu linux 12.10

canonical ubuntu linux 12.04

Vendor Advisories

Debian Bug report logs - #699825 CVE-2013-0240: fails to verify SSL certificates when creating accounts Package: gnome-online-accounts; Maintainer for gnome-online-accounts is Debian GNOME Maintainers <pkg-gnome-maintainers@listsaliothdebianorg>; Source for gnome-online-accounts is src:gnome-online-accounts (PTS, buildd, popcon) ...
GNOME Online Accounts could be made to expose sensitive information over the network ...