CVE Database
/

CVE-2020-13645

Back to search

CVE-2020-13645

Published: May 28, 2020

Modified: Aug 4, 2024

PUBLISHED

Description

In GNOME glib-networking through 2.64.2, the implementation of GTlsClientConnection skips hostname verification of the server's TLS certificate if the application fails to specify the expected server identity. This is in contrast to its intended documented behavior, to fail the certificate verification. Applications that fail to provide the server identity, including Balsa before 2.5.11 and 2.6.x before 2.6.1, accept a TLS certificate if the certificate is valid for any host.

VendorProductVersions

n/a

n/a

affected
n/a

References

FEDORA-2020-98ebbd1397
vendor-advisory
x_refsource_FEDORA
FEDORA-2020-cadbc5992f
vendor-advisory
x_refsource_FEDORA
FEDORA-2020-a83c8cd358
vendor-advisory
x_refsource_FEDORA
USN-4405-1
vendor-advisory
x_refsource_UBUNTU
GLSA-202007-50
vendor-advisory
x_refsource_GENTOO

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now