libgdata is prone to a security-bypass vulnerability because the application fails to properly validate SSL certificates from the server
Credit:
The original article can be found at: http://www.securityfocus.com/bid/52504
The information has been provided by Arthur Gerkis, Chamal de Silva, wushi of team509, and miaubiz. .
Successfully exploiting this issue allows attackers to perform man-in-the-middle attacks or impersonate trusted servers, which will aid in further attacks.libgdata 0.10 is vulnerable; other versions may also be available.
Vendor Status:
Vendor as issued an updated vulnerability.