[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

251139

 
 

909

 
 

196159

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-4964-1 grilo -- grilo

ID: oval:org.secpod.oval:def:605614Date: (C)2021-08-30   (M)2023-11-24
Class: PATCHFamily: unix




Michael Catanzaro reported a problem in Grilo, a framework for discovering and browsing media. TLS certificate verification is not enabled on the SoupSessionAsync objects created by Grilo, leaving users vulnerable to network MITM attacks.

Platform:
Debian 10.x
Debian 11.x
Product:
gir1.2-grilo-0.3
libgrilo-0.3-0
libgrilo-0.3-bin
libgrilo-0.3-dev
libgrilo-0.3-doc
Reference:
DSA-4964-1
CVE-2021-39365
CVE    1
CVE-2021-39365

© SecPod Technologies