|
|
| |
|
| |
telepathy-gabble: denial of service
| Package(s): | telepathy-gabble |
CVE #(s): | CVE-2013-1769
|
| Created: | March 14, 2013 |
Updated: | March 22, 2013 |
| Description: |
From the Red Hat bugzilla:
So we have a remotely-triggered DoS: send Gabble a <presence> with a caps hash;
include a form with an anonymous fixed field in the reply; boom. Since anyone
can send presence to anyone else, and Gabble always looks up any caps it sees
in any presences it receives. (Note that this is a presence leak, too; another
bug, I think.) |
| Alerts: |
|
( Log in to post comments)
|
|
|