Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <51113C76.6040907@debian.org>
Date: Tue, 05 Feb 2013 17:08:06 +0000
From: Simon McVittie <smcv@...ian.org>
To: oss-security@...ts.openwall.com
Subject: Re: [CVE Assignment Notification] CVE-2013-0240 -
 Gnome Online Accounts (GOA) (previously) failed to verify SSL certificates
 when creating e.g. Windows Live or Facebook accounts

On 05/02/13 16:12, Jan Lieskovsky wrote:
>   it was found that Gnome Online Accounts (GOA)
> did not perform SSL certificate validation, when
> performing Windows Live and Facebook accounts creation.
...
> The CVE identifier of CVE-2013-0240 has been assigned
> to this issue.

Now that this is public, I've opened GNOME bug
https://bugzilla.gnome.org/show_bug.cgi?id=693214 to track this bug and
its fixes for the various available branches.

    S

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.