Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2021-39365
Description:In GNOME grilo though 0.3.13, grl-net-wc.c does not enable TLS certificate verification on the SoupSessionAsync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.
Test IDs: 1.3.6.1.4.1.25623.1.1.2.2022.2561   1.3.6.1.4.1.25623.1.1.2.2022.1567   1.3.6.1.4.1.25623.1.0.854182   1.3.6.1.4.1.25623.1.1.4.2021.3194.1   1.3.6.1.4.1.25623.1.0.845039   1.3.6.1.4.1.25623.1.1.10.2021.0472   1.3.6.1.4.1.25623.1.1.2.2022.1535   1.3.6.1.4.1.25623.1.1.4.2021.3295.1   1.3.6.1.4.1.25623.1.1.4.2021.3003.1   1.3.6.1.4.1.25623.1.1.2.2023.1750   1.3.6.1.4.1.25623.1.0.892762   1.3.6.1.4.1.25623.1.0.854190   1.3.6.1.4.1.25623.1.1.2.2023.1087   1.3.6.1.4.1.25623.1.0.704964   1.3.6.1.4.1.25623.1.1.2.2022.2503  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2021-39365
Debian Security Information: DSA-4964 (Google Search)
https://www.debian.org/security/2021/dsa-4964
https://blogs.gnome.org/mcatanzaro/2021/05/25/reminder-soupsessionsync-and-soupsessionasync-default-to-no-tls-certificate-verification/
https://gitlab.gnome.org/GNOME/grilo/-/issues/146
https://lists.debian.org/debian-lts-announce/2021/09/msg00010.html




© 1998-2025 E-Soft Inc. All rights reserved.