Advisories ยป MGASA-2021-0504

Updated libzapojit packages fix security vulnerability

Publication date: 10 Nov 2021
Modification date: 10 Nov 2021
Type: security
Affected Mageia releases : 8
CVE: CVE-2021-39360

Description

In GNOME libzapojit through 0.0.3, zpj-skydrive.c does not enable TLS
certificate verification on the SoupSessionSync objects it creates,
leaving users vulnerable to network MITM attacks. (CVE-2021-39360)
                

References

SRPMS

8/core