MGASA-2013-0170
Dashboard / Vulnerabilities / MGASA-2013-0170
Summary: Updated telepathy-gabble package fixes security vulnerability
Details: Maksim Otstavnov discovered that the Wocky submodule used by telepathy-gabble does not respect the tls-required flag on legacy Jabber servers. A network intermediary could use this vulnerability to bypass TLS verification and perform a man-in-the-middle attack.
References: https://advisories.mageia.org/MGASA-2013-0170.html, https://bugs.mageia.org/show_bug.cgi?id=10432, http://www.debian.org/security/2013/dsa-2702, http://lists.freedesktop.org/archives/telepathy/2013-May/006450.html, http://lists.freedesktop.org/archives/telepathy/2013-May/006449.html
Affected packages
Package
Name: telepathy-gabble
Purl: pkg:rpm/mageia/telepathy-gabble?arch=source&distro=mageia-2
Affected ranges
Type: ECOSYSTEM
Events:
