Skip to content

GitLab

  • Menu
Projects Groups Snippets
    • Loading...
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
    • Contribute to GitLab
  • Sign in / Register
  • Adélie Package Tree Adélie Package Tree
  • Project information
    • Project information
    • Activity
    • Labels
    • Members
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributors
    • Graph
    • Compare
  • Issues 309
    • Issues 309
    • List
    • Boards
    • Service Desk
    • Milestones
  • Merge requests 21
    • Merge requests 21
  • CI/CD
    • CI/CD
    • Pipelines
    • Jobs
    • Schedules
  • Deployments
    • Deployments
    • Releases
  • Activity
  • Graph
  • Create a new issue
  • Jobs
  • Commits
  • Issue Boards
Collapse sidebar
  • Adélie Linux
  • Adélie Package TreeAdélie Package Tree
  • Issues
  • #308

Closed
Open
Created Jun 19, 2020 by Emily@emily🤖

user/glib-networking: CVE-2020-13645: TLS certificate hostname verification not performed by default

Bugzilla ID 308
Alias(es) CVE-2020-13645
Reporter Max Rees (sroracle)
Assignee Max Rees (sroracle)
Reported 2020-06-18 21:23:57 -0500
Modified 2020-09-16 22:43:36 -0500
Status RESOLVED FIXED
Version 1.0-RC1
Hardware Adélie Linux / All
Importance --- / normal
Package(s) user/glib-networking
URL https://nvd.nist.gov/vuln/detail/CVE-2020-13645

Description

In GNOME glib-networking through 2.64.2, the implementation of
GTlsClientConnection skips hostname verification of the server's TLS
certificate if the application fails to specify the expected server
identity. This is in contrast to its intended documented behavior, to
fail the certificate verification. Applications that fail to provide
the server identity, including Balsa before 2.5.11 and 2.6.x before
2.6.1, accept a TLS certificate if the certificate is valid for any
host.

Fixed in >= 2.64.3 https://gitlab.gnome.org/GNOME/glib-networking/-/commit/dbc8d69f58b07f6ed091aa123e5d40a53573a5fc

Edited Feb 02, 2022 by Zach van Rijn
Assignee
Assign to
Time tracking