Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.841126
Category:Ubuntu Local Security Checks
Title:Ubuntu: Security Advisory (USN-1547-1)
Summary:The remote host is missing an update for the 'evolution-data-server, libgdata' package(s) announced via the USN-1547-1 advisory.
Description:Summary:
The remote host is missing an update for the 'evolution-data-server, libgdata' package(s) announced via the USN-1547-1 advisory.

Vulnerability Insight:
Vreixo Formoso discovered that the libGData library, as used
by Evolution and other applications, did not properly verify SSL
certificates. A remote attacker could exploit this to perform a man
in the middle attack to view sensitive information or alter data
transmitted via the GData protocol.

Affected Software/OS:
'evolution-data-server, libgdata' package(s) on Ubuntu 10.04, Ubuntu 11.04, Ubuntu 11.10.

Solution:
Please install the updated package(s).

CVSS Score:
5.1

CVSS Vector:
AV:N/AC:H/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2012-1177
50432
http://secunia.com/advisories/50432
DSA-2482
http://www.debian.org/security/2012/dsa-2482
MDVSA-2012:111
http://www.mandriva.com/security/advisories?name=MDVSA-2012:111
USN-1547-1
http://www.ubuntu.com/usn/USN-1547-1
[oss-security] 20120314 CVE Request: libgdata did not verify SSL certificates
http://www.openwall.com/lists/oss-security/2012/03/14/1
[oss-security] 20120314 Re: CVE Request: libgdata did not verify SSL certificates
http://www.openwall.com/lists/oss-security/2012/03/14/3
http://www.openwall.com/lists/oss-security/2012/03/14/8
http://git.gnome.org/browse/libgdata/commit/?h=libgdata-0-10&id=8eff8fa9138859e03e58c2aa76600ab63eb5c29c
http://git.gnome.org/browse/libgdata/commit/?id=6799f2c525a584dc998821a6ce897e463dad7840
https://bugs.launchpad.net/ubuntu/+source/libgdata/+bug/938812
https://bugzilla.gnome.org/show_bug.cgi?id=671535
https://bugzilla.novell.com/show_bug.cgi?id=752088
CopyrightCopyright (C) 2012 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.