drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Mangelnde Echtheitsprüfung in telepathy-gabble
Name: |
Mangelnde Echtheitsprüfung in telepathy-gabble |
|
ID: |
FEDORA-2011-1284 |
|
Distribution: |
Fedora |
|
Plattformen: |
Fedora 15 |
|
Datum: |
Do, 3. März 2011, 06:58 |
|
Referenzen: |
Keine Angabe |
|
Applikationen: |
telepathy-gabble |
|
Originalnachricht |
Name : telepathy-gabble Product : Fedora 15 Version : 0.11.7 Release : 1.fc15 URL : http://telepathy.freedesktop.org/wiki/ Summary : A Jabber/XMPP connection manager Description : A Jabber/XMPP connection manager, that handles single and multi-user chats and voice calls.
------------------------------------------------------------------------------- - Update Information:
Telepathy-Gabble changes, including a security fix: * fd.o#32390: Gabble now treats a request for a ContactSearch channel with Server set to the empty string as equivalent to not specifying a server, and rejects requests where the JID specified for Server is invalid. * fd.o#32874: Offline contacts are now assumed to support 1–1 text channels. * fd.o#34048: Malicious contacts can no longer trick Gabble into relaying audio/video data via a server of their choosing. * fd.o#32815: fallback-conference-server now defaults to conference.telepathy.im. Thus, if the user's server doesn't have a conference component configured, upgrading a 1-1 chat into an ad-hoc conference still works. * fd.o#11291: support for xep-0092, Software Version. * fd.o#33471: support for the FileTransfer.URI property.
Telepathy-Glib Enhancements include: * Many doc fixes, including: TpBaseClientClass is now included; INCOMING_MESSAGES is now explained. * Compiler flags reordered (clang is order-sensitive) to allow static analysis. * Account Channel Requests now give you access to the originating TpChannelRequest. * The speculative debug cache may now be disabled at compile time. tp_debug_sender_add_message_vprintf and tp_debug_sender_add_message_printf added to allow callers who care about optimisation to reduce debug overhead. ------------------------------------------------------------------------------- -
This update can be installed with the "yum" update program. Use su -c 'yum update telepathy-gabble' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys ------------------------------------------------------------------------------- - _______________________________________________ package-announce mailing list package-announce@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/package-announce
|
|
|
|