gwibber-bugs team mailing list archive
-
gwibber-bugs team
-
Mailing list archive
-
Message #00291
[Bug 705363] [NEW] gwibber bypasses certificate checking when providing the login/password for OAuth
*** This bug is a security vulnerability ***
Public security bug reported:
Someone reported this in Debian: http://bugs.debian.org/cgi-
bin/bugreport.cgi?bug=608724
identi.ca had (mistakenly) installed an SSL certificate not recognized
by the installed CA, yet the user has been presented with the OAuth
login screen even if that https connection could not be authentified.
** Affects: gwibber
Importance: Undecided
Status: New
** Affects: gwibber (Debian)
Importance: Unknown
Status: Unknown
** Visibility changed to: Public
** Bug watch added: Debian Bug tracker #608724
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=608724
** Also affects: gwibber (Debian) via
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=608724
Importance: Unknown
Status: Unknown
--
You received this bug notification because you are a member of Gwibber
Bug Heros, which is subscribed to Gwibber.
https://bugs.launchpad.net/bugs/705363
Title:
gwibber bypasses certificate checking when providing the
login/password for OAuth
Status in Gwibber:
New
Status in “gwibber” package in Debian:
Unknown
Bug description:
Someone reported this in Debian: http://bugs.debian.org/cgi-
bin/bugreport.cgi?bug=608724
identi.ca had (mistakenly) installed an SSL certificate not recognized
by the installed CA, yet the user has been presented with the OAuth
login screen even if that https connection could not be authentified.
Follow ups
-
[Bug 705363] Re: gwibber bypasses certificate checking when providing the login/password for OAuth
From: Bug Watch Updater, 2015-09-14
-
[Bug 705363] Re: gwibber bypasses certificate checking when providing the login/password for OAuth
From: Ken VanDine, 2012-10-17
-
[Bug 705363] Re: gwibber bypasses certificate checking when providing the login/password for OAuth
From: Raphaël Hertzog, 2012-05-19
-
[Bug 705363] Re: gwibber bypasses certificate checking when providing the login/password for OAuth
From: Bilal Shahid, 2012-05-17
-
[Bug 705363] Re: gwibber bypasses certificate checking when providing the login/password for OAuth
From: Rodney Dawes, 2012-03-20
-
[Bug 705363] Re: gwibber bypasses certificate checking when providing the login/password for OAuth
From: Launchpad Bug Tracker, 2012-02-26
-
[Bug 705363] Re: gwibber bypasses certificate checking when providing the login/password for OAuth
From: Andrew Starr-Bochicchio, 2012-02-26
-
[Bug 705363] Re: gwibber bypasses certificate checking when providing the login/password for OAuth
From: Evgeni Golov, 2012-01-01
-
[Bug 705363] Re: gwibber bypasses certificate checking when providing the login/password for OAuth
From: Evgeni Golov, 2011-06-12
-
[Bug 705363] Re: gwibber bypasses certificate checking when providing the login/password for OAuth
From: Kartik Mistry, 2011-06-04
-
[Bug 705363] Re: gwibber bypasses certificate checking when providing the login/password for OAuth
From: Bug Watch Updater, 2011-01-21
-
[Bug 705363] [NEW] gwibber bypasses certificate checking when providing the login/password for OAuth
From: Raphaël Hertzog, 2011-01-20
References