LWN.net Logo

Ubuntu alert USN-1250-1 (empathy)

From:  Steve Beattie <sbeattie@ubuntu.com>
To:  ubuntu-security-announce@lists.ubuntu.com
Subject:  [USN-1250-1] Empathy vulnerabilities
Date:  Fri, 28 Oct 2011 10:51:06 -0700
Message-ID:  <20111028175106.GB4845@nxnw.org>
Archive-link:  Article, Thread

========================================================================== Ubuntu Security Notice USN-1250-1 October 28, 2011 empathy vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 11.10 - Ubuntu 11.04 - Ubuntu 10.10 - Ubuntu 10.04 LTS Summary: Empathy could be made to run programs or display webpages via specially crafted nicknames. Software Description: - empathy: GNOME multi-protocol chat and call client Details: It was discovered that a cross-site scripting (XSS) vulnerability in the Adium theme allows remote attackers to inject arbitrary javascript or HTML via a crafted nickname in XMPP group conversations. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 11.10: empathy 3.2.0.1-0ubuntu1.1 Ubuntu 11.04: empathy 2.34.0-0ubuntu3.2 Ubuntu 10.10: empathy 2.32.1-0ubuntu1.2 Ubuntu 10.04 LTS: empathy 2.30.3-0ubuntu1.1 After a standard system update you need to restart your session to make all the necessary changes. References: http://www.ubuntu.com/usn/usn-1250-1 CVE-2011-3635, CVE-2011-4170 Package Information: https://launchpad.net/ubuntu/+source/empathy/3.2.0.1-0ubu... https://launchpad.net/ubuntu/+source/empathy/2.34.0-0ubun... https://launchpad.net/ubuntu/+source/empathy/2.32.1-0ubun... https://launchpad.net/ubuntu/+source/empathy/2.30.3-0ubun... -- ubuntu-security-announce mailing list ubuntu-security-announce@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security...


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds