Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cq2g-8982-9994

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Wocky module in Telepathy Gabble before 0.16.6 and 0.17.x before 0.17.4, when connecting to a "legacy Jabber server," does not properly enforce the WockyConnector:tls-required flag, which allows remote attackers to bypass TLS verification and perform a man-in-the-middle attacks.

The Wocky module in Telepathy Gabble before 0.16.6 and 0.17.x before 0.17.4, when connecting to a "legacy Jabber server," does not properly enforce the WockyConnector:tls-required flag, which allows remote attackers to bypass TLS verification and perform a man-in-the-middle attacks.

EPSS

Процентиль: 62%
0.00434
Низкий

Дефекты

CWE-20

Связанные уязвимости

ubuntu
почти 12 лет назад

The Wocky module in Telepathy Gabble before 0.16.6 and 0.17.x before 0.17.4, when connecting to a "legacy Jabber server," does not properly enforce the WockyConnector:tls-required flag, which allows remote attackers to bypass TLS verification and perform a man-in-the-middle attacks.

nvd
почти 12 лет назад

The Wocky module in Telepathy Gabble before 0.16.6 and 0.17.x before 0.17.4, when connecting to a "legacy Jabber server," does not properly enforce the WockyConnector:tls-required flag, which allows remote attackers to bypass TLS verification and perform a man-in-the-middle attacks.

debian
почти 12 лет назад

The Wocky module in Telepathy Gabble before 0.16.6 and 0.17.x before 0 ...

fstec
почти 12 лет назад

Уязвимости операционной системы Debian GNU/Linux, позволяющие удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 62%
0.00434
Низкий

Дефекты

CWE-20