CVE-2013-1431

medium
Published 2013-09-23 · Modified 2026-04-29
CVSS v3
CVSS v2
6.8
VIR risk
6.8

Description

The Wocky module in Telepathy Gabble before 0.16.6 and 0.17.x before 0.17.4, when connecting to a "legacy Jabber server," does not properly enforce the WockyConnector:tls-required flag, which allows remote attackers to bypass TLS verification and perform a man-in-the-middle attacks.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: security@debian.org — https://bugs.freedesktop.org/show_bug.cgi?id=65036

vendor Authored 2026-05-27

Vendor advisory: security@debian.org — http://seclists.org/oss-sec/2013/q2/438

Application impact

VendorProductVersionsFixed
simon_mcvittietelepathy_gabble{"endIncluding":"0.16.5"}
simon_mcvittietelepathy_gabble0.16.0
simon_mcvittietelepathy_gabble0.16.1
simon_mcvittietelepathy_gabble0.16.2
simon_mcvittietelepathy_gabble0.16.3
simon_mcvittietelepathy_gabble0.16.4
simon_mcvittietelepathy_gabble0.17.0
simon_mcvittietelepathy_gabble0.17.1
simon_mcvittietelepathy_gabble0.17.2
simon_mcvittietelepathy_gabble0.17.3

References

CWEs

CWE-20

Verify integrity in audit chain (admin only). AS-IS.