Lucene search

K
ubuntuUbuntuUSN-1821-1
HistoryMay 09, 2013 - 12:00 a.m.

telepathy-idle vulnerability

2013-05-0900:00:00
ubuntu.com
34

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

AI Score

6.3

Confidence

Low

EPSS

0.002

Percentile

58.6%

Releases

  • Ubuntu 13.04
  • Ubuntu 12.10
  • Ubuntu 12.04

Packages

  • telepathy-idle - IRC connection manager for Telepathy

Details

It was discovered that telepathy-idle did not perform any server
certificate validation when using SSL connections. If a remote attacker
were able to perform a machine-in-the-middle attack, this flaw could be
exploited to alter or compromise confidential information.

OSVersionArchitecturePackageVersionFilename
Ubuntu13.04noarchtelepathy-idle< 0.1.14-1ubuntu0.1UNKNOWN
Ubuntu12.10noarchtelepathy-idle< 0.1.12-1ubuntu0.1UNKNOWN
Ubuntu12.04noarchtelepathy-idle< 0.1.11-2ubuntu0.1UNKNOWN

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

AI Score

6.3

Confidence

Low

EPSS

0.002

Percentile

58.6%