CVE-2012-1177
Publication date 19 March 2012
Last updated 24 July 2024
Ubuntu priority
libgdata before 0.10.2 and 0.11.x before 0.11.1 does not validate SSL certificates, which allows remote attackers to obtain user names and passwords via a man-in-the-middle (MITM) attack with a spoofed certificate.
Status
Package | Ubuntu Release | Status |
---|---|---|
evolution-data-server | 12.04 LTS precise |
Not affected
|
11.10 oneiric |
Not affected
|
|
11.04 natty |
Not affected
|
|
10.04 LTS lucid |
Fixed 2.28.3.1-0ubuntu6.1
|
|
8.04 LTS hardy | Ignored end of life | |
libgdata | 12.04 LTS precise |
Not affected
|
11.10 oneiric |
Fixed 0.9.1-0ubuntu2.1
|
|
11.04 natty |
Fixed 0.8.0-0ubuntu1.1
|
|
10.10 maverick | Ignored end of life | |
10.04 LTS lucid |
Fixed 0.5.2-0ubuntu1.1
|
|
8.04 LTS hardy | Not in release |
References
Related Ubuntu Security Notices (USN)
- USN-1547-1
- libGData, evolution-data-server vulnerability
- 28 August 2012