CVE-2013-1799
published 2013-04-02CVE-2013-1799: Gnome Online Accounts (GOA) 3.6.x before 3.6.3 and 3.7.x before 3.7.91, does not properly validate SSL certificates when creating accounts for providers who…
PriorityP418medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
1.03%
60.3th percentile
Gnome Online Accounts (GOA) 3.6.x before 3.6.3 and 3.7.x before 3.7.91, does not properly validate SSL certificates when creating accounts for providers who use the libsoup library, which allows man-in-the-middle attackers to obtain sensitive information such as credentials by sniffing the network. NOTE: this issue exists because of an incomplete fix for CVE-2013-0240.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | gnome-online-accounts | — | — |
| gnome | gnome_online_accounts | — | — |
| gnome | gnome_online_accounts | — | — |
| gnome | gnome_online_accounts | — | — |
| gnome | gnome_online_accounts | — | — |
| gnome | gnome_online_accounts | — | — |
| gnome | gnome_online_accounts | — | — |
| gnome | gnome_online_accounts | — | — |
| gnome | gnome_online_accounts | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_debian4.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
GNOME Online Accounts vulnerability
vendor_ubuntu·2013-03-25
CVE-2013-0240 GNOME Online Accounts vulnerability
Title: GNOME Online Accounts vulnerability
Summary: GNOME Online Accounts could be made to expose sensitive information over
the network.
It was discovered that GNOME Online Accounts did not properly check SSL
certificates when configuring online accounts. If a remote attacker were
able to perform a machine-in-the-middle attack, this flaw could be exploited to
alter or compromise credentials and confidential information.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2013-1799: gnome-online-accounts - Gnome Online Accounts (GOA) 3.6.x before 3.6.3 and 3.7.x before 3.7.91, does not...
vendor_debian·2013·CVSS 4.3
CVE-2013-1799 [MEDIUM] CVE-2013-1799: gnome-online-accounts - Gnome Online Accounts (GOA) 3.6.x before 3.6.3 and 3.7.x before 3.7.91, does not...
Gnome Online Accounts (GOA) 3.6.x before 3.6.3 and 3.7.x before 3.7.91, does not properly validate SSL certificates when creating accounts for providers who use the libsoup library, which allows man-in-the-middle attackers to obtain sensitive information such as credentials by sniffing the network. NOTE: this issue exists because of an incomplete fix for CVE-2013-0240.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-346r-rmp5-4r78: Gnome Online Accounts (GOA) 3
ghsa_unreviewed·2022-05-17·CVSS 4.3
CVE-2013-1799 [MEDIUM] GHSA-346r-rmp5-4r78: Gnome Online Accounts (GOA) 3
Gnome Online Accounts (GOA) 3.6.x before 3.6.3 and 3.7.x before 3.7.91, does not properly validate SSL certificates when creating accounts for providers who use the libsoup library, which allows man-in-the-middle attackers to obtain sensitive information such as credentials by sniffing the network. NOTE: this issue exists because of an incomplete fix for CVE-2013-0240.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-updates/2013-02/msg00046.htmlhttp://secunia.com/advisories/51976http://secunia.com/advisories/52791http://ubuntu.com/usn/usn-1779-1https://bugzilla.gnome.org/show_bug.cgi?id=693214https://bugzilla.gnome.org/show_bug.cgi?id=695106https://git.gnome.org/browse/gnome-online-accounts/commit/?id=9cf4bc0ced2c53bcdd36922caa65afc8a167bbd8https://mail.gnome.org/archives/gnome-announce-list/2013-March/msg00007.htmlhttps://mail.gnome.org/archives/gnome-announce-list/2013-March/msg00020.htmlhttp://lists.opensuse.org/opensuse-updates/2013-02/msg00046.htmlhttp://secunia.com/advisories/51976http://secunia.com/advisories/52791http://ubuntu.com/usn/usn-1779-1https://bugzilla.gnome.org/show_bug.cgi?id=693214https://bugzilla.gnome.org/show_bug.cgi?id=695106https://git.gnome.org/browse/gnome-online-accounts/commit/?id=9cf4bc0ced2c53bcdd36922caa65afc8a167bbd8https://mail.gnome.org/archives/gnome-announce-list/2013-March/msg00007.htmlhttps://mail.gnome.org/archives/gnome-announce-list/2013-March/msg00020.html
2013-04-02
Published