CVE-2011-1000

Publication date 16 February 2011

Last updated 24 July 2024


Ubuntu priority

jingle-factory.c in Telepathy Gabble 0.11 before 0.11.7, 0.10 before 0.10.5, and 0.8 before 0.8.15 allows remote attackers to sniff audio and video calls via a crafted google:jingleinfo stanza that specifies an alternate server for streamed media.

Status

Package Ubuntu Release Status
telepathy-gabble 11.10 oneiric
Fixed 0.11.6-1ubuntu2
11.04 natty
Fixed 0.11.6-1ubuntu2
10.10 maverick
Fixed 0.10.0-1ubuntu0.1
10.04 LTS lucid
Fixed 0.8.12-0ubuntu1.1
9.10 karmic
Fixed 0.8.7-1ubuntu1.1
8.04 LTS hardy Ignored end of life
6.06 LTS dapper Not in release

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
telepathy-gabble