Vulnerability Details CVE-2013-1431
The Wocky module in Telepathy Gabble before 0.16.6 and 0.17.x before 0.17.4, when connecting to a "legacy Jabber server," does not properly enforce the WockyConnector:tls-required flag, which allows remote attackers to bypass TLS verification and perform a man-in-the-middle attacks.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 62.1%
CVSS Severity
CVSS v2 Score 6.8
Products affected by CVE-2013-1431
-
cpe:2.3:a:simon_mcvittie:telepathy_gabble:0.16.0
-
cpe:2.3:a:simon_mcvittie:telepathy_gabble:0.16.1
-
cpe:2.3:a:simon_mcvittie:telepathy_gabble:0.16.2
-
cpe:2.3:a:simon_mcvittie:telepathy_gabble:0.16.3
-
cpe:2.3:a:simon_mcvittie:telepathy_gabble:0.16.4
-
cpe:2.3:a:simon_mcvittie:telepathy_gabble:0.16.5
-
cpe:2.3:a:simon_mcvittie:telepathy_gabble:0.17.0
-
cpe:2.3:a:simon_mcvittie:telepathy_gabble:0.17.1
-
cpe:2.3:a:simon_mcvittie:telepathy_gabble:0.17.2
-
cpe:2.3:a:simon_mcvittie:telepathy_gabble:0.17.3