PT-2011-2805 · Telepathy · Telepathy Gabble
Will Thompson
·
Published
2011-02-18
·
Updated
2024-06-15
·
CVE-2011-1000
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Telepathy Gabble versions 0.8 through 0.8.14
Telepathy Gabble versions 0.10 through 0.10.4
Telepathy Gabble versions 0.11 through 0.11.6
Description
The issue allows remote attackers to intercept audio and video calls by using a crafted google:jingleinfo stanza. This stanza specifies an alternate server for streamed media, enabling the attacker to sniff the calls.
Recommendations
For versions 0.8 through 0.8.14, update to version 0.8.15 or later.
For versions 0.10 through 0.10.4, update to version 0.10.5 or later.
For versions 0.11 through 0.11.6, update to version 0.11.7 or later.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Telepathy Gabble