Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 506
Alerts This Week
Warning Icon 1 506

Ubuntu 13.04 Security Notices: USN-1821-1 Telepathy-Idle Info Leak Risk

ubuntu
Calendar Grey May 9, 2013
Scroller Ubuntu
Confronting the memory-leak flaw in Fedora uncovers threats to confidential information leakage via HTTPS protocols.
telepathy-idle could be made to expose sensitive information over the network.

Summary

telepathy-idle could be made to expose sensitive information over the

network.

Software Description:

- telepathy-idle: IRC connection manager for Telepathy

Details:

It was discovered that telepathy-idle did not perform any server

certificate validation when using SSL connections. If a remote attacker

were able to perform a man-in-the-middle attack, this flaw could be

exploited to alter or compromise confidential information.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.04:
  telepathy-idle                  0.1.14-1ubuntu0.1

Ubuntu 12.10:
  telepathy-idle                  0.1.12-1ubuntu0.1

Ubuntu 12.04 LTS:
  telepathy-idle                  0.1.11-2ubuntu0.1

After a standard system update you need to restart your session to make all
the necessary changes.

References

https://ubuntu.com/security/notices/USN-1821-1

CVE-2007-6746

Severity
important
Lowest
Low
Medium
High
Critical

May 09, 2013

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.