ZeroHour

CVE-2016-20011

CVSS 3.1
7.5 high
EPSS
1%p72
Published
()
Modified
Description

libgrss through 0.7.0 fails to perform TLS certificate verification when downloading feeds, allowing remote attackers to manipulate the contents of feeds without detection. This occurs because of the default behavior of SoupSessionSync.

Vendors
gnome
Products
libgrss
Weakness
CWE-295
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.