CVE Database
/

CVE-2020-6750

Back to search

CVE-2020-6750

Published: Jan 9, 2020

Modified: Aug 4, 2024

PUBLISHED

Description

GSocketClient in GNOME GLib through 2.62.4 may occasionally connect directly to a target address instead of connecting via a proxy server when configured to do so, because the proxy_addr field is mishandled. This bug is timing-dependent and may occur only sporadically depending on network delays. The greatest security relevance is in use cases where a proxy is used to help with privacy/anonymity, even though there is no technical barrier to a direct connection. NOTE: versions before 2.60 are unaffected.

VendorProductVersions

n/a

n/a

affected
n/a

References

FEDORA-2020-339d413324
vendor-advisory
x_refsource_FEDORA
FEDORA-2020-c101a316ab
vendor-advisory
x_refsource_FEDORA
FEDORA-2020-092ef6572a
vendor-advisory
x_refsource_FEDORA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now