TLS/SSL Certification Validation Flaw in Shotwell by GNOME
CVE-2016-1000033
3.7LOW
Summary
Shotwell versions prior to 0.22.0 are susceptible to a vulnerability in TLS/SSL certification validation, enabling the possibility of man-in-the-middle attacks. This issue could allow attackers to intercept communications and validate their own certificates, posing significant risks to user data security. It is crucial for users to update to the latest version to mitigate this risk.
References
CVSS V3.1
Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved