DEBIAN-CVE-2013-0240

Source
https://security-tracker.debian.org/tracker/CVE-2013-0240
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2013-0240.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2013-0240
Upstream
Published
2013-04-02T03:22:21.037Z
Modified
2026-04-28T20:12:15.213467Z
Summary
[none]
Details

Gnome Online Accounts (GOA) 3.4.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.5, does not properly validate SSL certificates when creating accounts such as Windows Live and Facebook accounts, which allows man-in-the-middle attackers to obtain sensitive information such as credentials by sniffing the network.

References

Affected packages

Debian:11 / gnome-online-accounts

Package

Name
gnome-online-accounts
Purl
pkg:deb/debian/gnome-online-accounts?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.4.2-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2013-0240.json"

Debian:12 / gnome-online-accounts

Package

Name
gnome-online-accounts
Purl
pkg:deb/debian/gnome-online-accounts?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.4.2-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2013-0240.json"

Debian:13 / gnome-online-accounts

Package

Name
gnome-online-accounts
Purl
pkg:deb/debian/gnome-online-accounts?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.4.2-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2013-0240.json"

Debian:14 / gnome-online-accounts

Package

Name
gnome-online-accounts
Purl
pkg:deb/debian/gnome-online-accounts?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.4.2-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2013-0240.json"