Privacy Breach in GNOME GLib's GSocketClient due to Proxy Misconfiguration
CVE-2020-6750

5.9MEDIUM

Key Information:

Vendor
Gnome
Status
Vendor
CVE Published:
9 January 2020

Summary

The GSocketClient component of GNOME GLib, up to version 2.62.4, has a vulnerability that may allow it to bypass the specified proxy settings, connecting directly to a target address unexpectedly. This issue arises from improper management of the proxy_addr field and is contingent on timing and network delays, making it sporadic in nature. This poses a significant risk in scenarios where proxies are employed for privacy and anonymity, as direct connections could expose user activities or data.

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2020-6750 : Privacy Breach in GNOME GLib's GSocketClient due to Proxy Misconfiguration | SecurityVulnerability.io