*** This bug is a security vulnerability ***

You have been subscribed to a public security bug by Marc Deslauriers 
(mdeslaur):

I just requested CVE-2011-3635 for
https://bugzilla.gnome.org/show_bug.cgi?id=662035

I'm opening this bug to already let you know about this security issue
as Ubuntu is more affected than other distros as it ships an Adium theme
by default.

Here is the description of the CVE:

Empathy from version 2.25.3 to 3.2.1.1 is vulnerable to a HTML injection
bug in its chat window. Only version built with WebKit support (which
was optional before version 3.1.5.1) are affected. Also this doesn't
affect the default chat window, the vulnerability happens only when the
user has configured it to use an Adium theme (none are provided by
default).

Fix:
http://git.gnome.org/browse/empathy/commit/?id=739aca418457de752be13721218aaebc74bd9d36
Details: https://bugzilla.gnome.org/show_bug.cgi?id=662035

** Affects: empathy (Ubuntu)
     Importance: Undecided
         Status: New

-- 
HTML injection in nicknames
https://bugs.launchpad.net/bugs/879301
You received this bug notification because you are a member of Ubuntu Bugs, 
which is subscribed to the bug report.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to