Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2016:3218-1

Опубликовано: 21 дек. 2016
Источник: suse-cvrf

Описание

Security update for mcabber

This update for mcabber fixes the following issues:

  • Update to version 1.0.4 (changes since 1.0.2):
    • Check the origin of roster pushes (boo#1014976, CVE-2015-8688 (Gajim), https://gultsch.de/gajim_roster_push_and_message_interception.html)
    • Link with the tinfo library.
    • Fix default modules directory on OpenBSD.
    • Create the history log directory if it doesn't exist.
    • [OTR] Do not send empty subjects.
    • [UI] /set does not display password values anymore.
    • [MUC] Use nick to set the role.
    • Misc help/documentation updates.

Список пакетов

openSUSE Leap 42.2
mcabber-1.0.4-3.1
mcabber-devel-1.0.4-3.1

Описание

Gajim before 0.16.5 allows remote attackers to modify the roster and intercept messages via a crafted roster-push IQ stanza.


Затронутые продукты
openSUSE Leap 42.2:mcabber-1.0.4-3.1
openSUSE Leap 42.2:mcabber-devel-1.0.4-3.1

Ссылки