CVE-2013-0240
Publication date 5 February 2013
Last updated 24 July 2024
Ubuntu priority
Gnome Online Accounts (GOA) 3.4.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.5, does not properly validate SSL certificates when creating accounts such as Windows Live and Facebook accounts, which allows man-in-the-middle attackers to obtain sensitive information such as credentials by sniffing the network.
Status
Package | Ubuntu Release | Status |
---|---|---|
gnome-online-accounts | ||
Notes
mdeslaur
3.2 in oneiric and 3.4 in precise only have web backends, so the 3.4 patch will work. In 3.6+, more backends are available that may have invalid certs, but are desirable. The 3.7 patch adds a new configuration item, but this changes API.
jdstrand
note that CVE-2013-1799 is a result of an incomplete fix for this CVE (and pt2 of the patch for 3.6)
Patch details
Package | Patch details |
---|---|
gnome-online-accounts |
References
Related Ubuntu Security Notices (USN)
- USN-1779-1
- GNOME Online Accounts vulnerability
- 25 March 2013