Back to search
CVE-2012-2132
Published: Aug 20, 2012
Modified: Aug 6, 2024
PUBLISHED
Description
libsoup 2.32.2 and earlier does not validate certificates or clear the trust flag when the ssl-ca-file does not exist, which allows remote attackers to bypass authentication by connecting with a SSL connection.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
[oss-security] 20120424 Re: CVE Request: libsoup 2.32.2 sets ssl trusted flag despite no verification
mailing-list
x_refsource_MLIST
53232
vdb-entry
x_refsource_BID
[oss-security] 20120424 CVE Request: libsoup 2.32.2 sets ssl trusted flag despite no verification
mailing-list
x_refsource_MLIST
[oss-security] 20120430 Re: CVE Request: libsoup 2.32.2 sets ssl trusted flag despite no verification
mailing-list
x_refsource_MLIST
libsoup-ssl-poofing(75167)
vdb-entry
x_refsource_XF
[oss-security] 20120502 Re: CVE Request: libsoup 2.32.2 sets ssl trusted flag despite no verification
mailing-list
x_refsource_MLIST
https://bugzilla.gnome.org/show_bug.cgi?id=666280
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now