Lucene search

K
alpinelinuxAlpine Linux Development TeamALPINE:CVE-2021-39365
HistoryAug 22, 2021 - 10:15 p.m.

CVE-2021-39365

2021-08-2222:15:00
Alpine Linux Development Team
security.alpinelinux.org
20
gnome
grilo
network security
mitm
certificate verification

EPSS

0.003

Percentile

70.2%

In GNOME grilo though 0.3.13, grl-net-wc.c does not enable TLS certificate verification on the SoupSessionAsync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.

OSVersionArchitecturePackageVersionFilename
Alpine3.14-communitynoarchgrilo= 0.3.13-r1UNKNOWN