Release date: 2012-03-13
Updated on: 2012-03-23
Affected Systems:
GNOME libgdata 0.6
GNOME libgdata 0.1
Description:
--------------------------------------------------------------------------------
Bugtraq id: 52504
Libgdata is a GLib-based library that uses the GData protocol to access the online service APIs.
Libgdata has a Security Restriction Bypass Vulnerability in verifying the implementation of the server's SSL certificate. After successful exploitation, it can perform man-in-the-middle attacks or simulate trusted servers.
<* Source: vendor
Link: https://bugzilla.novell.com/show_bug.cgi? Id = 752088
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
GNOME
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.gnome.org/