CVE-2020-6750
published 2020-01-09CVE-2020-6750: GSocketClient in GNOME GLib through 2.62.4 may occasionally connect directly to a target address instead of connecting via a proxy server when configured to do…
PriorityP432medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
2.17%
80.3th percentile
GSocketClient in GNOME GLib through 2.62.4 may occasionally connect directly to a target address instead of connecting via a proxy server when configured to do so, because the proxy_addr field is mishandled. This bug is timing-dependent and may occur only sporadically depending on network delays. The greatest security relevance is in use cases where a proxy is used to help with privacy/anonymity, even though there is no technical barrier to a direct connection. NOTE: versions before 2.60 are unaffected.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glib2.0 | < glib2.0 2.62.5-1 (bookworm) | glib2.0 2.62.5-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| gnome | glib | 2.60.0 – 2.62.4 | — |
| msrc | cbl2_glib_2.71.0-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_msrc5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w778-hx63-vw7w: GSocketClient in GNOME GLib through 2
ghsa_unreviewed·2022-05-24
CVE-2020-6750 [MEDIUM] CWE-200 GHSA-w778-hx63-vw7w: GSocketClient in GNOME GLib through 2
GSocketClient in GNOME GLib through 2.62.4 may occasionally connect directly to a target address instead of connecting via a proxy server when configured to do so, because the proxy_addr field is mishandled. This bug is timing-dependent and may occur only sporadically depending on network delays. The greatest security relevance is in use cases where a proxy is used to help with privacy/anonymity, even though there is no technical barrier to a direct connection. NOTE: versions before 2.60 are unaffected.
OSV
CVE-2020-6750: GSocketClient in GNOME GLib through 2
osv·2020-01-09·CVSS 5.9
CVE-2020-6750 [MEDIUM] CVE-2020-6750: GSocketClient in GNOME GLib through 2
GSocketClient in GNOME GLib through 2.62.4 may occasionally connect directly to a target address instead of connecting via a proxy server when configured to do so, because the proxy_addr field is mishandled. This bug is timing-dependent and may occur only sporadically depending on network delays. The greatest security relevance is in use cases where a proxy is used to help with privacy/anonymity, even though there is no technical barrier to a direct connection. NOTE: versions before 2.60 are unaffected.
Microsoft
GSocketClient in GNOME GLib through 2.62.4 may occasionally connect directly to a target address instead of connecting via a proxy server when configured to do so because the proxy_addr field is misha
vendor_msrc·2020-01-14·CVSS 5.9
CVE-2020-6750 [MEDIUM] GSocketClient in GNOME GLib through 2.62.4 may occasionally connect directly to a target address instead of connecting via a proxy server when configured to do so because the proxy_addr field is misha
GSocketClient in GNOME GLib through 2.62.4 may occasionally connect directly to a target address instead of connecting via a proxy server when configured to do so because the proxy_addr field is mishandled. This bug is timing-dependent and may occur only sporadically depending on network delays. The greatest security relevance is in use cases where a proxy is used to help with privacy/anonymity even though there is no technical barrier to a direct connection. NOTE: versions before 2.60 are unaffected.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent a
Red Hat
glib: Mishandling of proxy_addr field in GSocketClient may lead to proxy being ignored
vendor_redhat·2020-01-09·CVSS 5.9
CVE-2020-6750 [MEDIUM] CWE-20 glib: Mishandling of proxy_addr field in GSocketClient may lead to proxy being ignored
glib: Mishandling of proxy_addr field in GSocketClient may lead to proxy being ignored
GSocketClient in GNOME GLib through 2.62.4 may occasionally connect directly to a target address instead of connecting via a proxy server when configured to do so, because the proxy_addr field is mishandled. This bug is timing-dependent and may occur only sporadically depending on network delays. The greatest security relevance is in use cases where a proxy is used to help with privacy/anonymity, even though there is no technical barrier to a direct connection. NOTE: versions before 2.60 are unaffected.
Statement: As per upstream versions of glib2 before 2.60 are unaffected, therefore glib2 package shipped with Red Hat Products are not affected by this flaw.
Package: glib (Red Hat Enterprise Linux 5)
Debian
CVE-2020-6750: glib2.0 - GSocketClient in GNOME GLib through 2.62.4 may occasionally connect directly to ...
vendor_debian·2020·CVSS 5.9
CVE-2020-6750 [MEDIUM] CVE-2020-6750: glib2.0 - GSocketClient in GNOME GLib through 2.62.4 may occasionally connect directly to ...
GSocketClient in GNOME GLib through 2.62.4 may occasionally connect directly to a target address instead of connecting via a proxy server when configured to do so, because the proxy_addr field is mishandled. This bug is timing-dependent and may occur only sporadically depending on network delays. The greatest security relevance is in use cases where a proxy is used to help with privacy/anonymity, even though there is no technical barrier to a direct connection. NOTE: versions before 2.60 are unaffected.
Scope: local
bookworm: resolved (fixed in 2.62.5-1)
bullseye: resolved (fixed in 2.62.5-1)
forky: resolved (fixed in 2.62.5-1)
sid: resolved (fixed in 2.62.5-1)
trixie: resolved (fixed in 2.62.5-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-6750 glib2: glib: Mishandling of proxy_addr field in GSocketClient may lead to proxy being ignored [fedora-all]
bugzilla·2020-01-14·CVSS 5.9
CVE-2020-6750 [MEDIUM] CVE-2020-6750 glib2: glib: Mishandling of proxy_addr field in GSocketClient may lead to proxy being ignored [fedora-all]
CVE-2020-6750 glib2: glib: Mishandling of proxy_addr field in GSocketClient may lead to proxy being ignored [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: thi
Bugzilla
CVE-2020-6750 glib: Mishandling of proxy_addr field in GSocketClient may lead to proxy being ignored
bugzilla·2020-01-13·CVSS 5.9
CVE-2020-6750 [MEDIUM] CVE-2020-6750 glib: Mishandling of proxy_addr field in GSocketClient may lead to proxy being ignored
CVE-2020-6750 glib: Mishandling of proxy_addr field in GSocketClient may lead to proxy being ignored
GSocketClient in GNOME GLib through 2.62.4 may occasionally connect directly to a target address instead of connecting via a proxy server when configured to do so, because the proxy_addr field is mishandled. This bug is timing-dependent and may occur only sporadically depending on network delays. The greatest security relevance is in use cases where a proxy is used to help with privacy/anonymity, even though there is no technical barrier to a direct connection. NOTE: versions before 2.60 are unaffected.
Upstream issue:
https://gitlab.gnome.org/GNOME/glib/issues/1989
References:
https://bugzilla.suse.com/show_bug.cgi?id=1160668
Discussion:
Created mingw-glib2 tracking bugs for this is
Bugzilla
CVE-2020-6750 mingw-glib2: glib: Mishandling of proxy_addr field in GSocketClient may lead to proxy being ignored [fedora-all]
bugzilla·2020-01-13·CVSS 5.9
CVE-2020-6750 [MEDIUM] CVE-2020-6750 mingw-glib2: glib: Mishandling of proxy_addr field in GSocketClient may lead to proxy being ignored [fedora-all]
CVE-2020-6750 mingw-glib2: glib: Mishandling of proxy_addr field in GSocketClient may lead to proxy being ignored [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOT
Bugzilla
CVE-2020-6750 mingw-glib2: glib: Mishandling of proxy_addr field in GSocketClient may lead to proxy being ignored [epel-7]
bugzilla·2020-01-13·CVSS 5.9
CVE-2020-6750 [MEDIUM] CVE-2020-6750 mingw-glib2: glib: Mishandling of proxy_addr field in GSocketClient may lead to proxy being ignored [epel-7]
CVE-2020-6750 mingw-glib2: glib: Mishandling of proxy_addr field in GSocketClient may lead to proxy being ignored [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion
https://bugzilla.suse.com/show_bug.cgi?id=1160668https://gitlab.gnome.org/GNOME/glib/issues/1989https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5RIFEDSRJ4P3WFCMDUOFQ2LEILZLMDW7/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KJMLGW55HOQXHMTIPH2PWXFRBNBWVO4W/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MEM7MMAXMWCDPUH4MTUZ763MBB64RRLJ/https://security.netapp.com/advisory/ntap-20200127-0001/https://bugzilla.suse.com/show_bug.cgi?id=1160668https://gitlab.gnome.org/GNOME/glib/issues/1989https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5RIFEDSRJ4P3WFCMDUOFQ2LEILZLMDW7/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KJMLGW55HOQXHMTIPH2PWXFRBNBWVO4W/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MEM7MMAXMWCDPUH4MTUZ763MBB64RRLJ/https://security.netapp.com/advisory/ntap-20200127-0001/
2020-01-09
Published