Описание
Security update for mcabber
This update for mcabber fixes the following issues:
- Update to version 1.0.4 (changes since 1.0.2):
- Check the origin of roster pushes (boo#1014976, CVE-2015-8688 (Gajim), https://gultsch.de/gajim_roster_push_and_message_interception.html)
- Link with the tinfo library.
- Fix default modules directory on OpenBSD.
- Create the history log directory if it doesn't exist.
- [OTR] Do not send empty subjects.
- [UI] /set does not display password values anymore.
- [MUC] Use nick to set the role.
- Misc help/documentation updates.
Список пакетов
openSUSE Leap 42.2
mcabber-1.0.4-3.1
mcabber-devel-1.0.4-3.1
Ссылки
- E-Mail link for openSUSE-SU-2016:3218-1
- SUSE Security Ratings
Описание
Gajim before 0.16.5 allows remote attackers to modify the roster and intercept messages via a crafted roster-push IQ stanza.
Затронутые продукты
openSUSE Leap 42.2:mcabber-1.0.4-3.1
openSUSE Leap 42.2:mcabber-devel-1.0.4-3.1
Ссылки
- CVE-2015-8688
- SUSE Bug 1014976
- SUSE Bug 960668