CVE-2020-6750 describes a timing-dependent vulnerability in GSocketClient within GNOME GLib versions 2.60 through 2.62.4, where it may sporadically bypass a configured proxy and connect directly to a target. This medium-severity flaw (CVSS 5.9) has a high impact on confidentiality, particularly in privacy-sensitive use cases, but requires high attack complexity. There is no evidence of active exploitation, public exploit code, or significant community discussion, indicating a low current threat level.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.60.0, <= 2.62.4CPE matchmatch criteria | cpe:2.3:a:gnome:glib:*:*:*:*:*:*:*:* | ||
30CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:* | ||
31CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2020-6750
Dec 14, 2021GSocketClient in GNOME GLib through 2.62.4 may occasionally connect directly to a target address instead of connecting via a proxy server when configured to do so because the proxy_addr field is mishandled. This bug is timing-dependent and may occur only sporadically depending on network delays. The greatest security relevance is in use cases where a proxy is used to help with privacy/anonymity even though there is no technical barrier to a direct connection. NOTE: versions before 2.60 are unaffected.
Jan 14, 2020glib: Mishandling of proxy_addr field in GSocketClient may lead to proxy being ignored
Jan 9, 2020