CVE-2011-1000 Information
Description
jingle-factory.c in Telepathy Gabble 0.11 before 0.11.7 0.10 before 0.10.5 and 0.8 before 0.8.15 allows remote attackers to sniff audio and video calls via a crafted google:jingleinfo stanza that specifies an alternate server for streamed media.
Reference
http://lists.fedoraproject.org/pipermail/package-announce/2011-February/054324.html http://lists.fedoraproject.org/pipermail/package-announce/2011-March/054409.html http://lists.fedoraproject.org/pipermail/package-announce/2011-March/054575.html http://secunia.com/advisories/43316 http://secunia.com/advisories/43369 http://secunia.com/advisories/43404 http://secunia.com/advisories/43485 http://secunia.com/advisories/43545 http://secunia.com/advisories/44023 http://www.debian.org/security/2011/dsa-2169 http://www.openwall.com/lists/oss-security/2011/02/17/4 http://www.openwall.com/lists/oss-security/2011/02/17/7 http://www.securityfocus.com/bid/46440 http://www.ubuntu.com/usn/USN-1067-1 http://www.vupen.com/english/advisories/2011/0412 http://www.vupen.com/english/advisories/2011/0428 http://www.vupen.com/english/advisories/2011/0537 http://www.vupen.com/english/advisories/2011/0572 http://www.vupen.com/english/advisories/2011/0901 https://bugs.freedesktop.org/show_bug.cgi?id=34048 https://exchange.xforce.ibmcloud.com/vulnerabilities/65523 https://hermes.opensuse.org/messages/7848248
Share on: