CVE-2013-1431
23.09.2013, 20:55
The Wocky module in Telepathy Gabble before 0.16.6 and 0.17.x before 0.17.4, when connecting to a "legacy Jabber server," does not properly enforce the WockyConnector:tls-required flag, which allows remote attackers to bypass TLS verification and perform a man-in-the-middle attacks.Enginsight
Vendor | Product | Version |
---|---|---|
simon_mcvittie | telepathy_gabble | 𝑥 ≤ 0.16.5 |
simon_mcvittie | telepathy_gabble | 0.16.0 |
simon_mcvittie | telepathy_gabble | 0.16.1 |
simon_mcvittie | telepathy_gabble | 0.16.2 |
simon_mcvittie | telepathy_gabble | 0.16.3 |
simon_mcvittie | telepathy_gabble | 0.16.4 |
simon_mcvittie | telepathy_gabble | 0.17.0 |
simon_mcvittie | telepathy_gabble | 0.17.1 |
simon_mcvittie | telepathy_gabble | 0.17.2 |
simon_mcvittie | telepathy_gabble | 0.17.3 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
References