|
|
| |
|
| |
telepathy-gabble: man-in-the-middle attack
| Package(s): | telepathy-gabble |
CVE #(s): | CVE-2013-1431
|
| Created: | June 4, 2013 |
Updated: | June 18, 2013 |
| Description: |
From the Debian advisory:
Maksim Otstavnov discovered that the Wocky submodule used by
telepathy-gabble, the Jabber/XMPP connection manager for the Telepathy
framework, does not respect the tls-required flag on legacy Jabber
servers. A network intermediary could use this vulnerability to bypass
TLS verification and perform a man-in-the-middle attack.
|
| Alerts: |
|
( Log in to post comments)
|
|
|