Privacy Breach in GNOME GLib's GSocketClient due to Proxy Misconfiguration
CVE-2020-6750
5.9MEDIUM
Summary
The GSocketClient component of GNOME GLib, up to version 2.62.4, has a vulnerability that may allow it to bypass the specified proxy settings, connecting directly to a target address unexpectedly. This issue arises from improper management of the proxy_addr field and is contingent on timing and network delays, making it sporadic in nature. This poses a significant risk in scenarios where proxies are employed for privacy and anonymity, as direct connections could expose user activities or data.
References
CVSS V3.1
Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved