PublicDateAtUSN: 2013-02-28 Candidate: CVE-2013-1769 PublicDate: 2014-01-21 18:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1769 http://lists.freedesktop.org/archives/telepathy/2013-March/006377.html https://ubuntu.com/security/notices/USN-1873-1 Description: A certain hashing algorithm in Telepathy Gabble 0.16.x before 0.16.5 and 0.17.x before 0.17.3 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted message. Ubuntu-Description: Notes: jdstrand> remotely trigged DoS in client software, arguably of 'low' priority mdeslaur> upstream bug 57521 contains another crasher fix. Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=702252 https://bugzilla.redhat.com/show_bug.cgi?id=915962 https://bugs.freedesktop.org/show_bug.cgi?id=61433 https://bugs.freedesktop.org/show_bug.cgi?id=57521 Priority: low Discovered-by: Assigned-to: mdeslaur CVSS: Patches_telepathy-gabble: upstream: http://cgit.freedesktop.org/telepathy/telepathy-gabble/commit/?id=0d908c122903a384882eff7de0e9ec6d6058d661 upstream: http://cgit.freedesktop.org/telepathy/telepathy-gabble/commit/?id=3b10a7f1b0fcb728210eb12231df8b1a4c289c3b upstream: http://cgit.freedesktop.org/wocky/commit/?id=099f5b1c7119d2d7d81970958fc8b8d19e3fc5e8 upstream: http://cgit.freedesktop.org/wocky/commit/?id=3e17bf71aa47e7fe52c7053ec5cf44836cf5bd03 upstream: http://cgit.freedesktop.org/wocky/commit/?id=565f2ed54f53adc7bd6793a0e746ceb349843408 upstream_telepathy-gabble: released (0.16.5,0.17.3) hardy_telepathy-gabble: ignored (reached end-of-life) lucid_telepathy-gabble: ignored (reached end-of-life) oneiric_telepathy-gabble: ignored (reached end-of-life) precise_telepathy-gabble: released (0.16.0-0ubuntu3.1) quantal_telepathy-gabble: released (0.16.1-2ubuntu0.1) raring_telepathy-gabble: not-affected (0.16.5-0ubuntu1) devel_telepathy-gabble: not-affected (0.16.5-0ubuntu1)