<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:cpe="http://cpe.mitre.org/language/2.0" xmlns:cvrf="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf" xmlns:cvrf-common="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/common" xmlns:cvssv2="http://scap.nist.gov/schema/cvss-v2/1.0" xmlns:cvssv3="https://www.first.org/cvss/cvss-v3.0.xsd" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:ns0="http://purl.org/dc/elements/1.1/" xmlns:prod="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/prod" xmlns:scap-core="http://scap.nist.gov/schema/scap-core/1.0" xmlns:sch="http://purl.oclc.org/dsdl/schematron" xmlns:vuln="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf">
  <DocumentTitle xml:lang="en">CVE-2016-20011</DocumentTitle>
  <DocumentType>SUSE CVE</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>SUSE CVE-2016-20011</ID>
    </Identification>
    <Status>Interim</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>24</Number>
        <Date>2024-07-29T10:08:57Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2021-05-30T13:49:46Z</InitialReleaseDate>
    <CurrentReleaseDate>2024-07-29T10:08:57Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf-cve.pl</Engine>
      <Date>2020-12-27T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="CVE" Type="Summary" Ordinal="1" xml:lang="en">CVE-2016-20011</Note>
    <Note Title="Mitre CVE Description" Type="Description" Ordinal="2" xml:lang="en">libgrss through 0.7.0 fails to perform TLS certificate verification when downloading feeds, allowing remote attackers to manipulate the contents of feeds without detection. This occurs because of the default behavior of SoupSessionSync.</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="4" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
  </DocumentNotes>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/prod">
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Desktop 15 SP3">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Workstation Extension 15 SP3">
        <FullProductName ProductID="SUSE Linux Enterprise Workstation Extension 15 SP3" CPE="cpe:/o:suse:sle-we:15:sp3">SUSE Linux Enterprise Workstation Extension 15 SP3</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Desktop 15 SP4">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Workstation Extension 15 SP4">
        <FullProductName ProductID="SUSE Linux Enterprise Workstation Extension 15 SP4" CPE="cpe:/o:suse:sle-we:15:sp4">SUSE Linux Enterprise Workstation Extension 15 SP4</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 15 SP3">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Workstation Extension 15 SP3">
        <FullProductName ProductID="SUSE Linux Enterprise Workstation Extension 15 SP3" CPE="cpe:/o:suse:sle-we:15:sp3">SUSE Linux Enterprise Workstation Extension 15 SP3</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 15 SP4">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Workstation Extension 15 SP4">
        <FullProductName ProductID="SUSE Linux Enterprise Workstation Extension 15 SP4" CPE="cpe:/o:suse:sle-we:15:sp4">SUSE Linux Enterprise Workstation Extension 15 SP4</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server for SAP Applications 15 SP3">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Workstation Extension 15 SP3">
        <FullProductName ProductID="SUSE Linux Enterprise Workstation Extension 15 SP3" CPE="cpe:/o:suse:sle-we:15:sp3">SUSE Linux Enterprise Workstation Extension 15 SP3</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server for SAP Applications 15 SP4">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Workstation Extension 15 SP4">
        <FullProductName ProductID="SUSE Linux Enterprise Workstation Extension 15 SP4" CPE="cpe:/o:suse:sle-we:15:sp4">SUSE Linux Enterprise Workstation Extension 15 SP4</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="libgrss">
      <FullProductName ProductID="libgrss" CPE="cpe:2.3:a:gnome:libgrss:*:*:*:*:*:*:*:*">libgrss</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libgrss-devel">
      <FullProductName ProductID="libgrss-devel">libgrss-devel</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libgrss0">
      <FullProductName ProductID="libgrss0">libgrss0</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="typelib-1_0-Grss-0_7">
      <FullProductName ProductID="typelib-1_0-Grss-0_7">typelib-1_0-Grss-0_7</FullProductName>
    </Branch>
    <Relationship ProductReference="libgrss-devel" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Workstation Extension 15 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Workstation Extension 15 SP3:libgrss-devel">libgrss-devel as a component of SUSE Linux Enterprise Workstation Extension 15 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libgrss0" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Workstation Extension 15 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Workstation Extension 15 SP3:libgrss0">libgrss0 as a component of SUSE Linux Enterprise Workstation Extension 15 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="typelib-1_0-Grss-0_7" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Workstation Extension 15 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Workstation Extension 15 SP3:typelib-1_0-Grss-0_7">typelib-1_0-Grss-0_7 as a component of SUSE Linux Enterprise Workstation Extension 15 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libgrss" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Workstation Extension 15 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Workstation Extension 15 SP3:libgrss">libgrss as a component of SUSE Linux Enterprise Workstation Extension 15 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libgrss-devel" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Workstation Extension 15 SP4">
      <FullProductName ProductID="SUSE Linux Enterprise Workstation Extension 15 SP4:libgrss-devel">libgrss-devel as a component of SUSE Linux Enterprise Workstation Extension 15 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="libgrss0" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Workstation Extension 15 SP4">
      <FullProductName ProductID="SUSE Linux Enterprise Workstation Extension 15 SP4:libgrss0">libgrss0 as a component of SUSE Linux Enterprise Workstation Extension 15 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="typelib-1_0-Grss-0_7" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Workstation Extension 15 SP4">
      <FullProductName ProductID="SUSE Linux Enterprise Workstation Extension 15 SP4:typelib-1_0-Grss-0_7">typelib-1_0-Grss-0_7 as a component of SUSE Linux Enterprise Workstation Extension 15 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="libgrss" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Workstation Extension 15 SP4">
      <FullProductName ProductID="SUSE Linux Enterprise Workstation Extension 15 SP4:libgrss">libgrss as a component of SUSE Linux Enterprise Workstation Extension 15 SP4</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">libgrss through 0.7.0 fails to perform TLS certificate verification when downloading feeds, allowing remote attackers to manipulate the contents of feeds without detection. This occurs because of the default behavior of SoupSessionSync.</Note>
    </Notes>
    <CVE>CVE-2016-20011</CVE>
    <ProductStatuses>
      <Status Type="Will Not Fix">
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP3:libgrss</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP3:libgrss-devel</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP3:libgrss0</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP3:typelib-1_0-Grss-0_7</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP4:libgrss</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP4:libgrss-devel</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP4:libgrss0</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP4:typelib-1_0-Grss-0_7</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>5</BaseScoreV2>
        <VectorV2>AV:N/AC:L/Au:N/C:N/I:P/A:N</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>6.8</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
  </Vulnerability>
</cvrfdoc>
