libgdata before 0.10.2 and 0.11.x before 0.11.1 does not validate SSL certificates, which allows remote attackers to obtain user names and passwords via a man-in-the-middle (MITM) attack with a spoofed certificate.
CVSS Details
- CVSS 3.1 Base Score: 5.6
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libgdata | Jul 30, 2024 | Aug 26, 2012 |
| Gentoo Linux | — | Upgrade dev-libs/libgdata. | Oct 30, 2017 | Aug 26, 2012 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Mar 12, 2012 |
| Suse | — | Upgrade libgdata-develUpgrade libgdata13-debuginfo-x86Upgrade libgdata13-32bitUpgrade libgdata13Upgrade libgdata-debugsourceUpgrade libgdata13-debuginfo-x86-debuginfoUpgrade libgdata13-debuginfo-32bitUpgrade libgdata13-debuginfoUpgrade libgdata13-x86Upgrade libgdata-langUpgrade libgdata | Dec 12, 2013 | Aug 26, 2012 |
| Ubuntu | — | Upgrade libgdata13Upgrade libgdata6Upgrade libgdata1.2-1Upgrade libgdata-google1.2-1Upgrade libgdata11 | Nov 8, 2024 | Aug 26, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub