CVE-2012-2132: Medium severity libsoup vulnerability
Published Aug 20, 2012
·Updated
libsoup 2.32.2 and earlier does not validate certificates or clear the trust flag when the ssl-ca-file does not exist, which allows remote attackers to bypass authentication by connecting with a SSL connection.
Affected Software
1 affected component
Gnome libsoup=2.32.2
Event History
Aug 20, 2012
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-2132?
CVE-2012-2132 is considered a moderate severity vulnerability due to its potential for bypassing SSL authentication.
2
How do I fix CVE-2012-2132?
To fix CVE-2012-2132, upgrade to a later version of libsoup that includes SSL certificate validation improvements.
3
What versions of libsoup are affected by CVE-2012-2132?
libsoup versions 2.32.2 and earlier are affected by CVE-2012-2132.
4
What are the consequences of CVE-2012-2132?
The consequences of CVE-2012-2132 include the risk of remote attackers bypassing authentication on SSL connections.
5
Is CVE-2012-2132 still a threat today?
CVE-2012-2132 poses a threat to systems using outdated versions of libsoup that have not been patched or upgraded.