In GNOME libzapojit through 0.0.3, zpj-skydrive.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.
{ "binaries": [ { "binary_name": "gir1.2-zpj-0.0", "binary_version": "0.0.3-1ubuntu1" }, { "binary_name": "libzapojit-0.0-0", "binary_version": "0.0.3-1ubuntu1" }, { "binary_name": "libzapojit-dev", "binary_version": "0.0.3-1ubuntu1" } ] }
{ "binaries": [ { "binary_name": "gir1.2-zpj-0.0", "binary_version": "0.0.3-4" }, { "binary_name": "libzapojit-0.0-0", "binary_version": "0.0.3-4" }, { "binary_name": "libzapojit-dev", "binary_version": "0.0.3-4" } ] }
{ "binaries": [ { "binary_name": "gir1.2-zpj-0.0", "binary_version": "0.0.3-5" }, { "binary_name": "libzapojit-0.0-0", "binary_version": "0.0.3-5" }, { "binary_name": "libzapojit-dev", "binary_version": "0.0.3-5" } ] }