MGASA-2021-0504

Source
https://advisories.mageia.org/MGASA-2021-0504.html
Import Source
https://advisories.mageia.org/MGASA-2021-0504.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2021-0504
Related
Published
2021-11-10T22:53:34Z
Modified
2021-11-10T22:17:18Z
Summary
Updated libzapojit packages fix security vulnerability
Details

In GNOME libzapojit through 0.0.3, zpj-skydrive.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. (CVE-2021-39360)

References
Credits

Affected packages

Mageia:8 / libzapojit

Package

Name
libzapojit
Purl
pkg:rpm/mageia/libzapojit?arch=source&distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.0.3-9.1.mga8

Ecosystem specific

{
    "section": "core"
}