Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

Ubuntu 13.04 LTS: USN-1873-1 Critical: Telepathy-Gabble Threats

ubuntu
Calendar Grey June 12, 2013
Scroller Ubuntu
Security update USN-1932-2 tackles flaws in telepathy-gabble impacting various Ubuntu versions.
Several security issues were fixed in telepathy-gabble.

Summary

Several security issues were fixed in telepathy-gabble.

Software Description:

- telepathy-gabble: Jabber/XMPP connection manager

Details:

Maksim Otstavnov discovered that telepathy-gabble incorrectly handled

TLS when connecting to legacy jabber servers. If a remote attacker were

able to perform a man-in-the-middle attack, this flaw could be exploited to

view sensitive information. (CVE-2013-1431)

It was discovered that telepathy-gabble incorrectly handled certain

messages. A remote attacker could use this flaw to cause applications using

telepathy-gabble to crash, resulting in a denial of service. This issue

only affected Ubuntu 12.04 LTS and Ubuntu 12.10. (CVE-2013-1769)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.04:
  telepathy-gabble                0.16.5-0ubuntu1.1

Ubuntu 12.10:
  telepathy-gabble                0.16.1-2ubuntu0.1

Ubuntu 12.04 LTS:
  telepathy-gabble                0.16.0-0ubuntu3.1

After a standard system update you need to restart your session to make all
the necessary changes.

References

https://ubuntu.com/security/notices/USN-1873-1

CVE-2013-1431, CVE-2013-1769

Severity
critical
Lowest
Low
Medium
High
Critical

June 12, 2013

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.