CVE-2020-6750

MEDIUM

GNOME GLib 2.60.0-2.62.4 - Proxy Bypass via GSocketClient Address Mishandling

Title source: llm
STIX 2.1

Description

GSocketClient in GNOME GLib through 2.62.4 may occasionally connect directly to a target address instead of connecting via a proxy server when configured to do so, because the proxy_addr field is mishandled. This bug is timing-dependent and may occur only sporadically depending on network delays. The greatest security relevance is in use cases where a proxy is used to help with privacy/anonymity, even though there is no technical barrier to a direct connection. NOTE: versions before 2.60 are unaffected.

References (6)

Core 6
Core References
Exploit, Issue Tracking, Vendor Advisory x_refsource_misc
https://gitlab.gnome.org/GNOME/glib/issues/1989
Issue Tracking, Third Party Advisory x_refsource_confirm
https://bugzilla.suse.com/show_bug.cgi?id=1160668
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20200127-0001/

Scores

CVSS v3 5.9
EPSS 0.0059
EPSS Percentile 69.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

Status published
Products (3)
fedoraproject/fedora 30
fedoraproject/fedora 31
gnome/glib 2.60.0 - 2.62.4
Published Jan 09, 2020
Tracked Since Feb 18, 2026