PT-2011-2805 · Telepathy · Telepathy Gabble

Will Thompson

·

Published

2011-02-18

·

Updated

2024-06-15

·

CVE-2011-1000

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Telepathy Gabble versions 0.8 through 0.8.14 Telepathy Gabble versions 0.10 through 0.10.4 Telepathy Gabble versions 0.11 through 0.11.6
Description The issue allows remote attackers to intercept audio and video calls by using a crafted google:jingleinfo stanza. This stanza specifies an alternate server for streamed media, enabling the attacker to sniff the calls.
Recommendations For versions 0.8 through 0.8.14, update to version 0.8.15 or later. For versions 0.10 through 0.10.4, update to version 0.10.5 or later. For versions 0.11 through 0.11.6, update to version 0.11.7 or later.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-1000
DSA-2169-1
OPENSUSE-SU-2024:10079-1

Affected Products

Telepathy Gabble