4.3
CVSSv2

CVE-2013-1799

Published: 02/04/2013 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

Gnome Online Accounts (GOA) 3.6.x prior to 3.6.3 and 3.7.x prior to 3.7.91, does not properly validate SSL certificates when creating accounts for providers who use the libsoup library, which allows man-in-the-middle malicious users to obtain sensitive information such as credentials by sniffing the network. NOTE: this issue exists because of an incomplete fix for CVE-2013-0240.

Vulnerable Product Search on Vulmon Subscribe to Product

gnome gnome online accounts 3.6.0

gnome gnome online accounts 3.6.2

gnome gnome online accounts 3.6.1

gnome gnome online accounts 3.7.3

gnome gnome online accounts 3.7.4

gnome gnome online accounts 3.7.90

gnome gnome online accounts 3.7.2

gnome gnome online accounts 3.7.1

canonical ubuntu linux 11.10

canonical ubuntu linux 12.10

canonical ubuntu linux 12.04

Vendor Advisories

GNOME Online Accounts could be made to expose sensitive information over the network ...