U radu programskog paketa Telepathy-Gabble, distribuiranog s operacijskim sustavom Fedora 13, uočen je sigurnosni nedostatak. Riječ je o dijelu telepathy okruženja koji omogućuje podršku za Jabber/XMMP IM protokol. Nedostatak je posljedica nepravilnosti u datoteci "jingle-factory.c". Udaljeni napadač takvu situaciju može iskoristiti za prisluškivanje audio i video poziva. Budući da su dostupne ispravljene inačice spomenutog paketa, svim se korisnicima, u svrhu zaštite, savjetuje njihova instalacija.

--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2011-1903
2011-02-21 06:48:27
--------------------------------------------------------------------------------

Name        : telepathy-gabble
Product     : Fedora 13
Version     : 0.10.5
Release     : 1.fc13
URL         : http://telepathy.freedesktop.org/wiki/
Summary     : A Jabber/XMPP connection manager
Description :
A Jabber/XMPP connection manager, that handles single and multi-user
chats and voice calls.

--------------------------------------------------------------------------------
ChangeLog:

* Wed Feb 16 2011 Brian Pepple <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 0.10.5-1
- Update to 0.10.5.
- Bump min BR of glib2.
- Add requires on tp-mission-control. Refer to NEWS file.
- Add BR on cyrus-sasl-devel for wocky test.
- Add BR on libnice-devel
- Add BR for sqlite-devel.
- Bump min req for tp-glib.
- Drop fedora cert patch. Fixed upstream.
* Sat Jul 10 2010 Brian Pepple <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 0.9.11-2
- Add patch to use Fedora's ssl certs. (#600532)
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #678908 - CVE-2011-1000 Telepathy-Gabble: Audio and video calls
sniffing via crafted google:jingleinfo stanza [fedora-13]
        https://bugzilla.redhat.com/show_bug.cgi?id=678908
--------------------------------------------------------------------------------

This update can be installed with the "yum" update program.  Use 
su -c 'yum update telepathy-gabble' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
https://admin.fedoraproject.org/mailman/listinfo/package-announce


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2011-1903
2011-02-21 06:48:27
--------------------------------------------------------------------------------

Name        : telepathy-glib
Product     : Fedora 13
Version     : 0.11.16
Release     : 2.fc13
URL         : http://telepathy.freedesktop.org/wiki/FrontPage
Summary     : GLib bindings for Telepathy
Description :
Telepathy-glib is the glib bindings for the telepathy unified framework
for all forms of real time conversations, including instant messaging, IRC,
voice calls and video calls.

--------------------------------------------------------------------------------
ChangeLog:

* Sun Feb 20 2011 Brian Pepple <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 0.11.16-2
- Drop devel require on tp-glib-vala.
* Sun Feb 20 2011 Brian Pepple <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 0.11.16-1
- Update to 0.11.16.
- Bump min version of glib required.
* Tue Jun 22 2010 Brian Pepple <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 0.10.7-1
- Update to 0.10.7.
* Tue May 25 2010 Brian Pepple <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 0.10.6-1
- Update to 0.10.6.
* Wed Apr 28 2010 Brian Pepple <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 0.10.5-1
- Update to 0.10.5.
* Tue Apr 20 2010 Brian Pepple <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 0.10.4-1
- Update to 0.10.4.
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #678908 - CVE-2011-1000 Telepathy-Gabble: Audio and video calls
sniffing via crafted google:jingleinfo stanza [fedora-13]
        https://bugzilla.redhat.com/show_bug.cgi?id=678908
--------------------------------------------------------------------------------

This update can be installed with the "yum" update program.  Use 
su -c 'yum update telepathy-glib' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
https://admin.fedoraproject.org/mailman/listinfo/package-announce

Idi na vrh