Alerts This Week
Warning Icon 1 697
Alerts This Week
Warning Icon 1 697

Mageia: 2021-0472 Critical: Grilo TLS Certificate Verification Issue

mageia
Calendar Grey October 13, 2021
Dist Mageia Esm H88
Mageia 2021-0451 introduces a boost for OpenSSL, reinforcing SSL/TLS handshake protocols to thwart potential interception threats.
Michael Catanzaro reported a problem in Grilo, a framework for discovering and browsing media

Summary

Michael Catanzaro reported a problem in Grilo, a framework for discovering and browsing media. TLS certificate verification is not enabled on the SoupSessionAsync objects created by Grilo, leaving users vulnerable to network MITM attacks.

References

- https://bugs.mageia.org/show_bug.cgi?id=29423

- https://lists.debian.org/debian-security-announce/2021/msg00148.html

- https://ubuntu.com/security/notices/USN-5055-1

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/BHNVKGOZ7O6L44VYMLWYH5RN63ALIRV2/

- https://www.cve.org/CVERecord?id=CVE-2021-39365

Resolution

SRPMS

- 8/core/grilo-0.3.14-1.mga8

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 13 Oct 2021
URL: https://advisories.mageia.org/MGASA-2021-0472.html
Type: security
CVE: CVE-2021-39365

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here