[Full-disclosure] [SECURITY] [DSA 2482-1] libgdata security update



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- -------------------------------------------------------------------------
Debian Security Advisory DSA-2482-1 security@xxxxxxxxxx
http://www.debian.org/security/ Yves-Alexis Perez
June 2, 2012 http://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : libgdata
Vulnerability : insufficient certificate validation
Problem type : remote
Debian-specific: no
CVE ID : CVE-2012-2653
Debian Bug : 664032

Vreixo Formoso discovered that libgdata, a library used to access various
Google services, wasn't validating certificates against trusted system
root CAs when using an https connection.

For the stable distribution (squeeze), this problem has been fixed in
version 0.6.4-2+squeeze1.

For the testing distribution (wheezy), this problem has been fixed in
version 0.10.2-1.

For the unstable distribution (sid), this problem has been fixed in
version 0.10.2-1.

We recommend that you upgrade your libgdata packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/

Mailing list: debian-security-announce@xxxxxxxxxxxxxxxx
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEcBAEBAgAGBQJPyg+cAAoJEOxfUAG2iX570q8H/34iZgboRkiMBx82t6kaP5J+
xn0pP6ZfQqrGJUA9VeWegD3nFuNLG9LlxCmE5B+v743/+V891ctQ6UzCG2iL1xd4
z8eiij//E+2QhaZatrrd58HXBYQI+51/rPpJ3nE+5l3QxCNGwpE8P8D7dIae20SR
EFS5TJ4WzwYKt+cgEJVgPOH94l4KV69MJCDIwOYy79ZgYWT5lrfJ2pQ9Mw4mVtkg
Z8+pxZCeXhgEq7H5NrAZplfcjgxBb2ZiJG1naxmGhVNtuo2ybSuOHbGeTbOQ47q5
5ZSFKaafo+CzSOXXwWPzfPMbpRDBwPvdRZgpsKUaWbHLQwkDDNCi+xE5XRPB+Fo=
=WCiw
-----END PGP SIGNATURE-----

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/



Relevant Pages

  • [Full-disclosure] [SECURITY] [DSA 2482-1] arpwatch security update
    ... Vulnerability: insufficient certificate validation ... For the stable distribution, this problem has been fixed in ... We recommend that you upgrade your libgdata packages. ... Further information about Debian Security Advisories, ...
    (Full-Disclosure)
  • [SECURITY] [DSA 2482-1] arpwatch security update
    ... Vulnerability: insufficient certificate validation ... For the stable distribution, this problem has been fixed in ... We recommend that you upgrade your libgdata packages. ... Further information about Debian Security Advisories, ...
    (Bugtraq)
  • [SECURITY] [DSA 2482-1] libgdata security update
    ... Vulnerability: insufficient certificate validation ... For the stable distribution, this problem has been fixed in ... We recommend that you upgrade your libgdata packages. ... Further information about Debian Security Advisories, ...
    (Bugtraq)
  • Re: Getting started with Xen -- Xen enabled kernel for Lenny?
    ... I might be rushing in to conversation, but I will try to install Debian ... There is a problem for newer Debian kernels (as in ... the etch distribution) and Xen. ... virtualization and thus called DOM 0 meaning the virtualization machine ...
    (Debian-User)
  • Re: [announcement] SYSAPI and SYSSVC for Windows
    ... > hardware is supported. ... Then, Debian is for you. ... Use the stable distribution. ... I was referring to "package ...
    (comp.lang.ada)