The Wocky module in Telepathy Gabble before 0.16.6 and 0.17.x before 0.17.4, when connecting to a "legacy Jabber server," does not properly enforce the WockyConnector:tls-required flag, which allows remote attackers to bypass TLS verification and perform a man-in-the-middle attacks.
                
            References
                    | Link | Resource | 
|---|---|
| http://seclists.org/oss-sec/2013/q2/438 | Mailing List Patch | 
| http://secunia.com/advisories/53779 | Permissions Required Third Party Advisory | 
| http://www.debian.org/security/2013/dsa-2702 | Third Party Advisory | 
| http://www.ubuntu.com/usn/USN-1873-1 | Third Party Advisory | 
| https://bugs.freedesktop.org/show_bug.cgi?id=65036 | Patch | 
| http://seclists.org/oss-sec/2013/q2/438 | Mailing List Patch | 
| http://secunia.com/advisories/53779 | Permissions Required Third Party Advisory | 
| http://www.debian.org/security/2013/dsa-2702 | Third Party Advisory | 
| http://www.ubuntu.com/usn/USN-1873-1 | Third Party Advisory | 
| https://bugs.freedesktop.org/show_bug.cgi?id=65036 | Patch | 
Configurations
                    Configuration 1 (hide)
            
            
  | 
    
History
                    21 Nov 2024, 01:49
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () http://seclists.org/oss-sec/2013/q2/438 - Mailing List, Patch | |
| References | () http://secunia.com/advisories/53779 - Permissions Required, Third Party Advisory | |
| References | () http://www.debian.org/security/2013/dsa-2702 - Third Party Advisory | |
| References | () http://www.ubuntu.com/usn/USN-1873-1 - Third Party Advisory | |
| References | () https://bugs.freedesktop.org/show_bug.cgi?id=65036 - Patch | 
Information
                Published : 2013-09-23 20:55
Updated : 2025-04-11 00:51
NVD link : CVE-2013-1431
Mitre link : CVE-2013-1431
CVE.ORG link : CVE-2013-1431
JSON object : View
Products Affected
                simon_mcvittie
- telepathy_gabble
 
CWE
                
                    
                        
                        CWE-20
                        
            Improper Input Validation
