Bugzilla – Bug 1189839
VUL-0: CVE-2021-39365: grilo: missing TLS certificate verification
Last modified: 2024-05-13 18:40:41 UTC
In GNOME grilo though 0.3.13, grl-net-wc.c does not enable TLS certificate verification on the SoupSessionAsync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011. References: https://gitlab.gnome.org/GNOME/grilo/-/issues/146 https://blogs.gnome.org/mcatanzaro/2021/05/25/reminder-soupsessionsync-and-soupsessionasync-default-to-no-tls-certificate-verification/ References: https://bugzilla.redhat.com/show_bug.cgi?id=1997161 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-39365 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39365 http://www.cvedetails.com/cve/CVE-2021-39365/ https://blogs.gnome.org/mcatanzaro/2021/05/25/reminder-soupsessionsync-and-soupsessionasync-default-to-no-tls-certificate-verification/ https://gitlab.gnome.org/GNOME/grilo/-/issues/146
Affected packages: - SUSE:SLE-12-SP2:Update/grilo 0.3.2 - SUSE:SLE-15-SP2:Update/grilo 0.3.12 - SUSE:SLE-15:Update/grilo 0.3.4 - openSUSE:Factory/grilo 0.3.13 Upstream patch [0]. [0] https://gitlab.gnome.org/GNOME/grilo/-/commit/cd2472e506dafb1bb8ae510e34ad4797f63e263e
SR to GNOME:Factory https://build.opensuse.org/request/show/914469
https://build.suse.de/request/show/249081 to SLE-15 https://build.suse.de/request/show/249082 to SLE-12-SP2
# maintenance_jira_update_notice SUSE-SU-2021:3003-1: An update that fixes one vulnerability is now available. Category: security (important) Bug References: 1189839 CVE References: CVE-2021-39365 JIRA References: Sources used: SUSE Linux Enterprise Workstation Extension 12-SP5 (src): grilo-0.3.2-7.3.1 SUSE Linux Enterprise Software Development Kit 12-SP5 (src): grilo-0.3.2-7.3.1 SUSE Linux Enterprise Server 12-SP5 (src): grilo-0.3.2-7.3.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2021:3194-1: An update that fixes one vulnerability is now available. Category: security (important) Bug References: 1189839 CVE References: CVE-2021-39365 JIRA References: Sources used: SUSE Linux Enterprise Workstation Extension 15-SP3 (src): grilo-0.3.12-3.3.1 SUSE Linux Enterprise Workstation Extension 15-SP2 (src): grilo-0.3.12-3.3.1 SUSE Linux Enterprise Module for Desktop Applications 15-SP3 (src): grilo-0.3.12-3.3.1 SUSE Linux Enterprise Module for Desktop Applications 15-SP2 (src): grilo-0.3.12-3.3.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
openSUSE-SU-2021:3194-1: An update that fixes one vulnerability is now available. Category: security (important) Bug References: 1189839 CVE References: CVE-2021-39365 JIRA References: Sources used: openSUSE Leap 15.3 (src): grilo-0.3.12-3.3.1
openSUSE-SU-2021:1312-1: An update that fixes one vulnerability is now available. Category: security (important) Bug References: 1189839 CVE References: CVE-2021-39365 JIRA References: Sources used: openSUSE Leap 15.2 (src): grilo-0.3.12-lp152.2.3.1
SUSE-SU-2021:3295-1: An update that fixes one vulnerability is now available. Category: security (important) Bug References: 1189839 CVE References: CVE-2021-39365 JIRA References: Sources used: SUSE Linux Enterprise Server for SAP 15-SP1 (src): grilo-0.3.4-3.3.1 SUSE Linux Enterprise Server for SAP 15 (src): grilo-0.3.4-3.3.1 SUSE Linux Enterprise Server 15-SP1-LTSS (src): grilo-0.3.4-3.3.1 SUSE Linux Enterprise Server 15-SP1-BCL (src): grilo-0.3.4-3.3.1 SUSE Linux Enterprise Server 15-LTSS (src): grilo-0.3.4-3.3.1 SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (src): grilo-0.3.4-3.3.1 SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS (src): grilo-0.3.4-3.3.1 SUSE Linux Enterprise High Performance Computing 15-LTSS (src): grilo-0.3.4-3.3.1 SUSE Linux Enterprise High Performance Computing 15-ESPOS (src): grilo-0.3.4-3.3.1 SUSE Enterprise Storage 6 (src): grilo-0.3.4-3.3.1 SUSE CaaS Platform 4.0 (src): grilo-0.3.4-3.3.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.