CVE-2021-39358 (https://gitlab.gnome.org/GNOME/libgfbgraph/-/issues/17): In GNOME libgfbgraph through 0.2.4, gfbgraph-photo.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=7b5ce63ca04c9e2be5fed284f067670672adf9b6 commit 7b5ce63ca04c9e2be5fed284f067670672adf9b6 Author: Pacho Ramos <pacho@gentoo.org> AuthorDate: 2021-11-11 12:06:50 +0000 Commit: Pacho Ramos <pacho@gentoo.org> CommitDate: 2021-11-11 12:59:07 +0000 net-libs/libgfbgraph: Bump to 0.2.5 Bug: https://bugs.gentoo.org/809722 Package-Manager: Portage-3.0.28, Repoman-3.0.3 Signed-off-by: Pacho Ramos <pacho@gentoo.org> net-libs/libgfbgraph/Manifest | 1 + net-libs/libgfbgraph/libgfbgraph-0.2.5.ebuild | 53 +++++++++++++++++++++++++++ 2 files changed, 54 insertions(+)
Please file a stablereq when ready
Please cleanup
Clean.
Thanks!
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=707f9fb081e563f01250f5b0848924fda790c87a commit 707f9fb081e563f01250f5b0848924fda790c87a Author: David Seifert <soap@gentoo.org> AuthorDate: 2023-04-30 10:06:23 +0000 Commit: David Seifert <soap@gentoo.org> CommitDate: 2023-04-30 10:06:23 +0000 net-libs/libgfbgraph: treeclean Bug: https://bugs.gentoo.org/809722 Signed-off-by: David Seifert <soap@gentoo.org> net-libs/libgfbgraph/Manifest | 1 - net-libs/libgfbgraph/libgfbgraph-0.2.5.ebuild | 53 --------------------------- net-libs/libgfbgraph/metadata.xml | 11 ------ profiles/package.mask | 7 ---- 4 files changed, 72 deletions(-)