LWN.net Logo

gnome-online-accounts: information disclosure

Package(s):gnome-online-accounts CVE #(s):CVE-2013-0240
Created:February 15, 2013 Updated:March 25, 2013
Description:

From the openSUSE bug tracker:

It was found that Gnome Online Accounts (GOA) did not perform SSL certificate validation, when performing Windows Live and Facebook accounts creation. A remote attacker could use this flaw to conduct man-in-the-middle (MiTM) attacks, possibly leading to their ability to obtain sensitive information.

Alerts:
openSUSE openSUSE-SU-2013:0301-1 2013-02-15
Mageia MGASA-2013-0059 2013-02-21
Fedora FEDORA-2013-2202 2013-02-27
Fedora FEDORA-2013-3414 2013-03-19
Ubuntu USN-1779-1 2013-03-25

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds