UbuntuUpdates.org

Package "telepathy-gabble"

Name: telepathy-gabble

Description:

Jabber/XMPP connection manager

Latest version: 0.16.0-0ubuntu3.1
Release: precise (12.04)
Level: security
Repository: main
Homepage: http://telepathy.freedesktop.org/wiki/

Links


Download "telepathy-gabble"


Other versions of "telepathy-gabble" in Precise

Repository Area Version
base main 0.16.0-0ubuntu1
updates main 0.16.0-0ubuntu3.1

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 0.16.0-0ubuntu3.1 2013-06-12 15:09:23 UTC

  telepathy-gabble (0.16.0-0ubuntu3.1) precise-security; urgency=low

  * SECURITY UPDATE: multiple denial of service issues
    - debian/patches/CVE-2013-1769.patch: fix DoS issues in
      lib/ext/wocky/wocky/wocky-caps-hash.c,
      lib/ext/wocky/wocky/wocky-data-form.c,
      src/conn-presence.c.
    - CVE-2013-1769
  * SECURITY UPDATE: information disclosure via legacy Jabber TLS bypass
    - debian/patches/CVE-2013-1431.patch: validate TLS requests in
      lib/ext/wocky/wocky/wocky-connector.c, added tests to
      tests/twisted/Makefile.am, tests/twisted/gabbletest.py,
      tests/twisted/tls/legacy-jabber.py.
    - CVE-2013-1431
 -- Marc Deslauriers <email address hidden> Fri, 07 Jun 2013 09:27:20 -0400

CVE-2013-1769 Crashes when trying to hash caps containing pathological data forms



About   -   Send Feedback to @ubuntu_updates