CVE-2021-39358: Medium severity Gnome libgfbgraph vulnerability
Published Aug 22, 2021
·Updated
In GNOME libgfbgraph through 0.2.4, gfbgraph-photo.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.
Affected Software
4 affected components
Gnome libgfbgraph<=0.2.4
Fedoraproject Fedora=33
Fedoraproject Fedora=34
Fedoraproject Fedora=35
Event History
Aug 22, 2021
CVE Published
via MITRE·06:47 PM
Data Sourced
via MITRE·06:47 PM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-39358.
2
What is the severity level of CVE-2021-39358?
The severity level of CVE-2021-39358 is medium with a score of 5.9 out of 10.
3
How does CVE-2021-39358 impact users?
CVE-2021-39358 leaves users vulnerable to network MITM attacks.
4
Which software versions are affected by CVE-2021-39358?
Versions up to and including 0.2.4 of GNOME libgfbgraph and Fedora versions 33, 34, and 35 are affected by CVE-2021-39358.
5
How can users fix CVE-2021-39358?
Users can fix CVE-2021-39358 by updating to a patched version of GNOME libgfbgraph or upgrading to a newer version of Fedora.