CVE-2013-1431
Severity CVSS v4.0:
Pending analysis
Type:
CWE-20
Input Validation
Publication date:
23/09/2013
Last modified:
11/04/2025
Description
The Wocky module in Telepathy Gabble before 0.16.6 and 0.17.x before 0.17.4, when connecting to a "legacy Jabber server," does not properly enforce the WockyConnector:tls-required flag, which allows remote attackers to bypass TLS verification and perform a man-in-the-middle attacks.
Impact
Base Score 2.0
6.80
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:simon_mcvittie:telepathy_gabble:*:*:*:*:*:*:*:* | 0.16.5 (including) | |
cpe:2.3:a:simon_mcvittie:telepathy_gabble:0.16.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:simon_mcvittie:telepathy_gabble:0.16.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:simon_mcvittie:telepathy_gabble:0.16.2:*:*:*:*:*:*:* | ||
cpe:2.3:a:simon_mcvittie:telepathy_gabble:0.16.3:*:*:*:*:*:*:* | ||
cpe:2.3:a:simon_mcvittie:telepathy_gabble:0.16.4:*:*:*:*:*:*:* | ||
cpe:2.3:a:simon_mcvittie:telepathy_gabble:0.17.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:simon_mcvittie:telepathy_gabble:0.17.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:simon_mcvittie:telepathy_gabble:0.17.2:*:*:*:*:*:*:* | ||
cpe:2.3:a:simon_mcvittie:telepathy_gabble:0.17.3:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://seclists.org/oss-sec/2013/q2/438
- http://secunia.com/advisories/53779
- http://www.debian.org/security/2013/dsa-2702
- http://www.ubuntu.com/usn/USN-1873-1
- https://bugs.freedesktop.org/show_bug.cgi?id=65036
- http://seclists.org/oss-sec/2013/q2/438
- http://secunia.com/advisories/53779
- http://www.debian.org/security/2013/dsa-2702
- http://www.ubuntu.com/usn/USN-1873-1
- https://bugs.freedesktop.org/show_bug.cgi?id=65036