libgrss does not perform any TLS certificate verification because it uses the deprecated SoupSessionAsync, which requires manually enabling certificate verification, rather than a modern SoupSession that has good defaults (CVE-2016-20011). . MGASA-2021-0343 - Updated libgrss packages fix security vulnerability Publication date: 12 Jul 2021 URL: https://advisories.mageia.org/MGASA-2021-0343.html Type: security Affected Mageia releases: 7, 8 CVE: CVE-2016-20011 libgrss does not perform any TLS certificate verification because it uses the deprecated SoupSessionAsync, which requires manually enabling certificate verification, rather than a modern SoupSession that has good defaults (CVE-2016-20011). References: - https://bugs.mageia.org/show_bug.cgi?id=29092 - - https://www.cve.org/CVERecord?id=CVE-2016-20011 SRPMS: - 7/core/libgrss-0.7.0-2.1.mga7 - 8/core/libgrss-0.7.0-4.1.mga8 . libgrss has addressed concerns regarding TLS certificate verification within the Mageia environment. This update outlines essential information and steps for resolution.. libgrss, TLS issue, Mageia security update, certificate verification, moderate severity. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.