LWN.net Logo

telepathy-gabble: denial of service

Package(s):telepathy-gabble CVE #(s):CVE-2013-1769
Created:March 14, 2013 Updated:March 22, 2013
Description:

From the Red Hat bugzilla:

So we have a remotely-triggered DoS: send Gabble a <presence> with a caps hash; include a form with an anonymous fixed field in the reply; boom. Since anyone can send presence to anyone else, and Gabble always looks up any caps it sees in any presences it receives. (Note that this is a presence leak, too; another bug, I think.)

Alerts:
Fedora FEDORA-2013-3439 2013-03-14
Mageia MGASA-2013-0096 2013-03-16
Fedora FEDORA-2013-3379 2013-03-19
openSUSE openSUSE-SU-2013:0518-1 2013-03-22

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds