Vulnerability Name:

CVE-2012-2132 (CCN-75167)

Assigned:2012-04-24
Published:2012-04-24
Updated:2017-08-29
Summary:libsoup 2.32.2 and earlier does not validate certificates or clear the trust flag when the ssl-ca-file does not exist, which allows remote attackers to bypass authentication by connecting with a SSL connection.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)
3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-287
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2012-2132

Source: CCN
Type: GNOME Live! Web site
libsoup

Source: CCN
Type: oss-security: Ludwig Nussel | 24 Apr
CVE Request: libsoup 2.32.2 sets ssl trusted flag despite no verification

Source: MLIST
Type: UNKNOWN
[oss-security] 20120424 Re: CVE Request: libsoup 2.32.2 sets ssl trusted flag despite no verification

Source: MLIST
Type: UNKNOWN
[oss-security] 20120424 CVE Request: libsoup 2.32.2 sets ssl trusted flag despite no verification

Source: MLIST
Type: UNKNOWN
[oss-security] 20120430 Re: CVE Request: libsoup 2.32.2 sets ssl trusted flag despite no verification

Source: MLIST
Type: UNKNOWN
[oss-security] 20120502 Re: CVE Request: libsoup 2.32.2 sets ssl trusted flag despite no verification

Source: BID
Type: UNKNOWN
53232

Source: CCN
Type: BID-53232
libsoup SSL Certificate Validation Security Bypass Vulnerability

Source: CONFIRM
Type: UNKNOWN
https://bugzilla.gnome.org/show_bug.cgi?id=666280

Source: XF
Type: UNKNOWN
libsoup-ssl-poofing(75167)

Source: XF
Type: UNKNOWN
libsoup-ssl-poofing(75167)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:gnome:libsoup:2.32.2:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:gnome:libsoup:2.32.2:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20122132
    V
    CVE-2012-2132
    2022-05-20
    oval:org.opensuse.security:def:42381
    P
    Security update for the Linux Kernel (Important)
    2022-05-16
    oval:org.opensuse.security:def:31751
    P
    Security update for java-1_8_0-ibm (Important) (in QA)
    2022-01-04
    oval:org.opensuse.security:def:32217
    P
    Security update for samba (Important)
    2021-11-19
    oval:org.opensuse.security:def:31697
    P
    Security update for opensc (Important)
    2021-10-29
    oval:org.opensuse.security:def:26154
    P
    Security update for ncurses (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:31686
    P
    Security update for xen (Important)
    2021-09-23
    oval:org.opensuse.security:def:32195
    P
    Security update for sqlite3 (Important)
    2021-09-23
    oval:org.opensuse.security:def:26113
    P
    Security update for mysql-connector-java (Moderate)
    2021-08-30
    oval:org.opensuse.security:def:26110
    P
    Security update for aspell (Important)
    2021-08-25
    oval:org.opensuse.security:def:26101
    P
    Security update for php74 (Important)
    2021-08-06
    oval:org.opensuse.security:def:31659
    P
    Security update for qemu (Important)
    2021-07-29
    oval:org.opensuse.security:def:32156
    P
    Security update for the Linux Kernel (Live Patch 34 for SLE 12 SP3) (Important)
    2021-07-27
    oval:org.opensuse.security:def:42626
    P
    libsoup-2_4-1-2.32.2-4.13.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:36219
    P
    libsoup-2_4-1-2.32.2-4.13.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:32938
    P
    Security update for libX11 (Important)
    2021-06-08
    oval:org.opensuse.security:def:36488
    P
    libsoup-devel-2.32.2-4.13.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:32107
    P
    Security update for the Linux Kernel (Live Patch 32 for SLE 12 SP3) (Important)
    2021-06-04
    oval:org.opensuse.security:def:26053
    P
    Security update for libxml2 (Important)
    2021-05-19
    oval:org.opensuse.security:def:26049
    P
    Security update for lz4 (Important)
    2021-05-14
    oval:org.opensuse.security:def:26038
    P
    Security update for curl (Moderate)
    2021-04-28
    oval:org.opensuse.security:def:32899
    P
    Security update for xen (Important)
    2021-04-19
    oval:org.opensuse.security:def:26203
    P
    Security update for openldap2 (Important)
    2021-03-03
    oval:org.opensuse.security:def:32261
    P
    Security update for krb5-appl (Important)
    2021-02-19
    oval:org.opensuse.security:def:26194
    P
    Security update for java-1_7_1-ibm (Important)
    2021-02-18
    oval:org.opensuse.security:def:32139
    P
    Security update for sudo (Important)
    2021-01-26
    oval:org.opensuse.security:def:26037
    P
    Security update for the Linux Kernel (Important)
    2021-01-15
    oval:org.opensuse.security:def:31685
    P
    Security update for java-1_8_0-ibm (Moderate)
    2021-01-05
    oval:org.opensuse.security:def:25972
    P
    Security update for postgresql12 (Important)
    2020-12-04
    oval:org.opensuse.security:def:35974
    P
    libsoup-2_4-1-2.32.2-4.13.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:31771
    P
    Security update for MozillaFirefox, MozillaFirefox-branding-SLED, firefox-gcc5, mozilla-nss (Important)
    2020-12-01
    oval:org.opensuse.security:def:26447
    P
    Security update for pdns (Important)
    2020-12-01
    oval:org.opensuse.security:def:32295
    P
    Security update for ppp (Important)
    2020-12-01
    oval:org.opensuse.security:def:27217
    P
    libsoup-2_4-1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25525
    P
    Security update for ruby2.1 (Important)
    2020-12-01
    oval:org.opensuse.security:def:26463
    P
    Security update for enigmail (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32505
    P
    enscript on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25866
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:26769
    P
    libsoup-2_4-1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26242
    P
    Security update for ibus (Important)
    2020-12-01
    oval:org.opensuse.security:def:25844
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:26345
    P
    Security update for libgit2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32052
    P
    Security update for kvm (Important)
    2020-12-01
    oval:org.opensuse.security:def:26544
    P
    fetchmail on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26322
    P
    Security update for ffmpeg (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32439
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:25728
    P
    Security update for python-cffi, python-cryptography (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26716
    P
    gvim on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31453
    P
    Security update for postgresql10 (Low)
    2020-12-01
    oval:org.opensuse.security:def:27486
    P
    libsoup-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25769
    P
    Security update for gd (Low)
    2020-12-01
    oval:org.opensuse.security:def:31895
    P
    Security update for MozillaFirefox, mozilla-nspr (Important)
    2020-12-01
    oval:org.opensuse.security:def:26938
    P
    libQtWebKit4-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31903
    P
    Security update for fontconfig (Low)
    2020-12-01
    oval:org.opensuse.security:def:26486
    P
    Security update for pdns-recursor (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32351
    P
    Security update for squid (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25536
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:26614
    P
    mozilla-xulrunner190 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33143
    P
    libcgroup1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31441
    P
    Security update for pixman (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25950
    P
    Security update for evince (Important)
    2020-12-01
    oval:org.opensuse.security:def:26813
    P
    pyxml on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26256
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:26398
    P
    Security update for pdns-recursor (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27182
    P
    libexif on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25524
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:26379
    P
    Security update for irssi (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32461
    P
    Security update for xorg-x11-libXdmcp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25809
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:26755
    P
    libnetpbm10 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31527
    P
    Security update for Ruby
    2020-12-01
    oval:org.opensuse.security:def:25780
    P
    Security update for python (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32051
    P
    Security update for kvm (Important)
    2020-12-01
    oval:org.opensuse.security:def:26973
    P
    libsoup-2_4-1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31995
    P
    Security update for java-1_7_1-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:26500
    P
    Security update for ffmpeg-4 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26241
    P
    Security update for evolution (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32400
    P
    Security update for vim (Important)
    2020-12-01
    oval:org.opensuse.security:def:25600
    P
    Security update for java-1_8_0-ibm (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26667
    P
    apache2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33182
    P
    libsoup-2_4-1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31442
    P
    Security update for policycoreutils (Low)
    2020-12-01
    oval:org.opensuse.security:def:27451
    P
    libgtop-2_0-7-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25768
    P
    Security update for flash-player (Important)
    2020-12-01
    oval:org.opensuse.security:def:31808
    P
    Security update for apache2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26300
    P
    Security update for gimp (Moderate)
    2020-12-01
    oval:com.ubuntu.precise:def:20122132000
    V
    CVE-2012-2132 on Ubuntu 12.04 LTS (precise) - medium.
    2012-08-20
    BACK
    gnome libsoup 2.32.2
    gnome libsoup 2.32.2