Fix certificate validation to work without legacy CAs.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2017-bd15ca5490 2017-03-23 12:06:37.067033 -------------------------------------------------------------------------------- Name : empathy Product : Fedora 25 Version : 3.12.13 Release : 2.fc25 URL : Summary : Instant Messaging Client for GNOME Description : Empathy is powerful multi-protocol instant messaging client which supports Jabber, GTalk, MSN, IRC, Salut, and other protocols. It is built on top of the Telepathy framework. -------------------------------------------------------------------------------- Update Information: Fix certificate validation to work without legacy CAs. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1381671 - Fails to connect to Google, with legacy CAs disabled, or with ca-certificates version 2.10 https://bugzilla.redhat.com/show_bug.cgi?id=1381671 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade empathy' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Empathy could be made to run programs or display webpages via speciallycrafted nicknames.. =========================================================================Ubuntu Security Notice USN-1250-1 October 28, 2011 empathy vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 11.10 - Ubuntu 11.04 - Ubuntu 10.10 - Ubuntu 10.04 LTS Summary: Empathy could be made to run programs or display webpages via specially crafted nicknames. Software Description: - empathy: GNOME multi-protocol chat and call client Details: It was discovered that a cross-site scripting (XSS) vulnerability in the Adium theme allows remote attackers to inject arbitrary javascript or HTML via a crafted nickname in XMPP group conversations. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 11.10: empathy 3.2.0.1-0ubuntu1.1 Ubuntu 11.04: empathy 2.34.0-0ubuntu3.2 Ubuntu 10.10: empathy 2.32.1-0ubuntu1.2 Ubuntu 10.04 LTS: empathy 2.30.3-0ubuntu1.1 After a standard system update you need to restart your session to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-1250-1 CVE-2011-3635, CVE-2011-4170 Package Information: https://launchpad.net/ubuntu/+source/empathy/3.2.0.1-0ubuntu1.1 https://launchpad.net/ubuntu/+source/empathy/2.34.0-0ubuntu3.2 https://launchpad.net/ubuntu/+source/empathy/2.32.1-0ubuntu1.2 https://launchpad.net/ubuntu/+source/empathy/2.30.3-0ubuntu1.1 . Tackling several Empathy weaknesses in Ubuntu, notably an XSS threat through specially designed nicknames. Stay updated!. empathy vulnerabilities, XMPP security, Ubuntu security, remote execution. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.