Improper validation of certificate with host mismatch in glib-networking - CVE-2020-13645

 

Improper validation of certificate with host mismatch in glib-networking - CVE-2020-13645

Published: July 3, 2020


Vulnerability identifier: #VU29491
CSH Severity: Medium
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-13645
CWE-ID: CWE-297
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform MitM attack.

The vulnerability exists in GNOME glib-networking due to implementation of GTlsClientConnection skips hostname verification of the server's TLS certificate if the application fails to specify the expected server identity. A remote attacker can perform a Man-in-he-Middle (MitM) attack and gain access to sensitive information.


Affected software

glib-networking
Balsa
Gentoo Linux
SUSE CaaS Platform
SUSE MicroOS
SUSE Enterprise Storage
HPE Helion Openstack
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
Fedora
glib-networking (Alpine package)
glib-networking-debugsource
glib-networking-debuginfo
glib-networking
glib-networking-lang
mingw-glib-networking

How to mitigate CVE-2020-13645

Install updates from vendor's website.

glib-networking - update to 2.64.3
Balsa - addressed in versions 2.5.11, 2.6.1
glib-networking (Alpine package) - update to 2.64.3-r0
glib-networking-debugsource - addressed in versions 2.48.2-6.3.1, 2.54.1-3.6.1, 2.62.4-3.3.1
glib-networking-debuginfo - addressed in versions 2.48.2-6.3.1, 2.54.1-3.6.1, 2.62.4-3.3.1
glib-networking - addressed in versions 2.48.2-6.3.1, 2.54.1-3.6.1, 2.62.4-3.3.1
glib-networking-lang - addressed in versions 2.48.2-6.3.1, 2.54.1-3.6.1, 2.62.4-3.3.1
glib-networking - update to 2.62.4-1.fc31
mingw-glib-networking - addressed in versions 2.62.4-1.fc31, 2.64.3-1.fc32

External References

Related Security Bulletins