Improper validation of certificate with host mismatch in glib-networking - CVE-2020-13645
Published: July 3, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform MitM attack.
The vulnerability exists in GNOME glib-networking due to implementation of GTlsClientConnection skips hostname verification of
the server's TLS certificate if the application fails to specify the
expected server identity. A remote attacker can perform a Man-in-he-Middle (MitM) attack and gain access to sensitive information.
Affected software
Balsa
Gentoo Linux
SUSE CaaS Platform
SUSE MicroOS
SUSE Enterprise Storage
HPE Helion Openstack
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
Fedora
glib-networking (Alpine package)
glib-networking-debugsource
glib-networking-debuginfo
glib-networking
glib-networking-lang
mingw-glib-networking
How to mitigate CVE-2020-13645
Balsa - addressed in versions 2.5.11, 2.6.1
glib-networking (Alpine package) - update to 2.64.3-r0
glib-networking-debugsource - addressed in versions 2.48.2-6.3.1, 2.54.1-3.6.1, 2.62.4-3.3.1
glib-networking-debuginfo - addressed in versions 2.48.2-6.3.1, 2.54.1-3.6.1, 2.62.4-3.3.1
glib-networking - addressed in versions 2.48.2-6.3.1, 2.54.1-3.6.1, 2.62.4-3.3.1
glib-networking-lang - addressed in versions 2.48.2-6.3.1, 2.54.1-3.6.1, 2.62.4-3.3.1
glib-networking - update to 2.62.4-1.fc31
mingw-glib-networking - addressed in versions 2.62.4-1.fc31, 2.64.3-1.fc32
External References
- https://gitlab.gnome.org/GNOME/balsa/-/issues/34
- https://gitlab.gnome.org/GNOME/glib-networking/-/issues/135
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HLEX2IP62SU6WJ4SK3U766XGLQK3J62O/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TQEQJQ4XFMFCFJTEXKL2ZO3UELBPCKSK/
- https://security.netapp.com/advisory/ntap-20200608-0004/
Related Security Bulletins
- MitM attack in GNOME glib-networking
- MitM attack in GNOME Balsa
- Gentoo update for GLib Networking
- Improper validation of certificate with host mismatch in glib-networking (Alpine package)
- SUSE update for glib-networking
- SUSE update for glib-networking
- SUSE update for glib-networking
- Fedora 31 update for glib-networking
- Fedora 31 update for mingw-glib-networking
- Fedora 32 update for mingw-glib-networking