Red Hat Bugzilla – Bug 803335
CVE-2012-1177 libgdata: Absent validation of SSL certificates
Last modified: 2015-07-31 02:48:50 EDT
It was found that previously libgdata, a GLib-based library for accessing online service APIs using the GData protocol, did not perform SSL certificates validation even for secured connections. An application, linked against the libgdata library and holding the trust about the other side of the connection being the valid owner of the certificate, could be tricked into accepting of a spoofed SSL certificate by mistake (MITM attack).
Upstream bug report:
 https://bugzilla.gnome.org/show_bug.cgi?id=671535 (private)
 https://bugzilla.novell.com/show_bug.cgi?id=752088 (private)
Credit: Issue originally reported by Vreixo Formoso.
This issue affects the version of the libgdata package, as shipped with Red Hat Enterprise Linux 6.
This issue affects the versions of the libgdata package, as shipped with Fedora release of 15 and 16. Please schedule an update.
Created libgdata tracking bugs for this issue
Affects: fedora-all [bug 803337]
This was assigned the name CVE-2012-1177:
The Red Hat Security Response Team has rated this issue as having moderate security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.