CVE-2013-0240
published 2013-04-02CVE-2013-0240: Gnome Online Accounts (GOA) 3.4.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.5, does not properly validate SSL certificates when creating accounts such as…
PriorityP419medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
1.36%
69.1th percentile
Gnome Online Accounts (GOA) 3.4.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.5, does not properly validate SSL certificates when creating accounts such as Windows Live and Facebook accounts, which allows man-in-the-middle attackers to obtain sensitive information such as credentials by sniffing the network.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | gnome-online-accounts | < gnome-online-accounts 3.4.2-2 (bookworm) | gnome-online-accounts 3.4.2-2 (bookworm) |
| debian | gnome-online-accounts | — | — |
| gnome | gnome_online_accounts | — | — |
| gnome | gnome_online_accounts | — | — |
| gnome | gnome_online_accounts | — | — |
| gnome | gnome_online_accounts | — | — |
| gnome | gnome_online_accounts | — | — |
| gnome | gnome_online_accounts | — | — |
| gnome | gnome_online_accounts | — | — |
| gnome | gnome_online_accounts | — | — |
| gnome | gnome_online_accounts | — | — |
| gnome | gnome_online_accounts | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv4.3MEDIUM
vendor_debian4.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
GNOME Online Accounts vulnerability
vendor_ubuntu·2013-03-25
CVE-2013-0240 GNOME Online Accounts vulnerability
Title: GNOME Online Accounts vulnerability
Summary: GNOME Online Accounts could be made to expose sensitive information over
the network.
It was discovered that GNOME Online Accounts did not properly check SSL
certificates when configuring online accounts. If a remote attacker were
able to perform a machine-in-the-middle attack, this flaw could be exploited to
alter or compromise credentials and confidential information.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2013-0240: gnome-online-accounts - Gnome Online Accounts (GOA) 3.4.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.5, d...
vendor_debian·2013·CVSS 4.3
CVE-2013-0240 [MEDIUM] CVE-2013-0240: gnome-online-accounts - Gnome Online Accounts (GOA) 3.4.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.5, d...
Gnome Online Accounts (GOA) 3.4.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.5, does not properly validate SSL certificates when creating accounts such as Windows Live and Facebook accounts, which allows man-in-the-middle attackers to obtain sensitive information such as credentials by sniffing the network.
Scope: local
bookworm: resolved (fixed in 3.4.2-2)
bullseye: resolved (fixed in 3.4.2-2)
forky: resolved (fixed in 3.4.2-2)
sid: resolved (fixed in 3.4.2-2)
trixie: resolved (fixed in 3.4.2-2)
Debian
CVE-2013-1799: gnome-online-accounts - Gnome Online Accounts (GOA) 3.6.x before 3.6.3 and 3.7.x before 3.7.91, does not...
vendor_debian·2013·CVSS 4.3
CVE-2013-1799 [MEDIUM] CVE-2013-1799: gnome-online-accounts - Gnome Online Accounts (GOA) 3.6.x before 3.6.3 and 3.7.x before 3.7.91, does not...
Gnome Online Accounts (GOA) 3.6.x before 3.6.3 and 3.7.x before 3.7.91, does not properly validate SSL certificates when creating accounts for providers who use the libsoup library, which allows man-in-the-middle attackers to obtain sensitive information such as credentials by sniffing the network. NOTE: this issue exists because of an incomplete fix for CVE-2013-0240.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-346r-rmp5-4r78: Gnome Online Accounts (GOA) 3
ghsa_unreviewed·2022-05-17·CVSS 4.3
CVE-2013-1799 [MEDIUM] GHSA-346r-rmp5-4r78: Gnome Online Accounts (GOA) 3
Gnome Online Accounts (GOA) 3.6.x before 3.6.3 and 3.7.x before 3.7.91, does not properly validate SSL certificates when creating accounts for providers who use the libsoup library, which allows man-in-the-middle attackers to obtain sensitive information such as credentials by sniffing the network. NOTE: this issue exists because of an incomplete fix for CVE-2013-0240.
GHSA
GHSA-8224-8w2m-q535: Gnome Online Accounts (GOA) 3
ghsa_unreviewed·2022-05-05
CVE-2013-0240 [MEDIUM] GHSA-8224-8w2m-q535: Gnome Online Accounts (GOA) 3
Gnome Online Accounts (GOA) 3.4.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.5, does not properly validate SSL certificates when creating accounts such as Windows Live and Facebook accounts, which allows man-in-the-middle attackers to obtain sensitive information such as credentials by sniffing the network.
OSV
CVE-2013-0240: Gnome Online Accounts (GOA) 3
osv·2013-04-02·CVSS 4.3
CVE-2013-0240 [MEDIUM] CVE-2013-0240: Gnome Online Accounts (GOA) 3
Gnome Online Accounts (GOA) 3.4.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.5, does not properly validate SSL certificates when creating accounts such as Windows Live and Facebook accounts, which allows man-in-the-middle attackers to obtain sensitive information such as credentials by sniffing the network.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-updates/2013-02/msg00046.htmlhttp://secunia.com/advisories/51976http://secunia.com/advisories/52791http://ubuntu.com/usn/usn-1779-1https://bugzilla.gnome.org/show_bug.cgi?id=693214https://bugzilla.redhat.com/show_bug.cgi?id=894352https://git.gnome.org/browse/gnome-online-accounts/commit/?h=gnome-3-6&id=ecad8142e9ac519b9fc74b96dcb5531052bbffe1https://git.gnome.org/browse/gnome-online-accounts/commit/?id=bc10fdb68f75f8be84eb698ada08743b9c7c248fhttps://git.gnome.org/browse/gnome-online-accounts/commit/?id=edde7c63326242a60a075341d3fea0be0bc4d80ehttps://mail.gnome.org/archives/gnome-announce-list/2013-March/msg00007.htmlhttp://lists.opensuse.org/opensuse-updates/2013-02/msg00046.htmlhttp://secunia.com/advisories/51976http://secunia.com/advisories/52791http://ubuntu.com/usn/usn-1779-1https://bugzilla.gnome.org/show_bug.cgi?id=693214https://bugzilla.redhat.com/show_bug.cgi?id=894352https://git.gnome.org/browse/gnome-online-accounts/commit/?h=gnome-3-6&id=ecad8142e9ac519b9fc74b96dcb5531052bbffe1https://git.gnome.org/browse/gnome-online-accounts/commit/?id=bc10fdb68f75f8be84eb698ada08743b9c7c248fhttps://git.gnome.org/browse/gnome-online-accounts/commit/?id=edde7c63326242a60a075341d3fea0be0bc4d80ehttps://mail.gnome.org/archives/gnome-announce-list/2013-March/msg00007.html
2013-04-02
Published