gnome-online-accounts: information disclosure
| Package(s): | gnome-online-accounts | CVE #(s): | CVE-2013-0240 | ||||||||||||||||||||
| Created: | February 15, 2013 | Updated: | March 25, 2013 | ||||||||||||||||||||
| Description: | From the openSUSE bug tracker: It was found that Gnome Online Accounts (GOA) did not perform SSL certificate validation, when performing Windows Live and Facebook accounts creation. A remote attacker could use this flaw to conduct man-in-the-middle (MiTM) attacks, possibly leading to their ability to obtain sensitive information. | ||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||
