Debian Security Advisory

DSA-3492-2 gajim -- security update

Date Reported:
28 Feb 2016
Affected Packages:
gajim
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 816158.
More information:

The wheezy part of the previous gajim update, DSA-3492-1, was incorrectly built resulting in an unsatisfiable dependency. This update corrects that problem. For reference, the original advisory text follows.

Daniel Gultsch discovered a vulnerability in Gajim, an XMPP/jabber client. Gajim didn't verify the origin of roster update, allowing an attacker to spoof them and potentially allowing her to intercept messages.

For the oldstable distribution (wheezy), this problem has been fixed in version 0.15.1-4.1+deb7u2.

For the stable distribution (jessie), this problem has been fixed in version 0.16-1+deb8u1.

For the testing distribution (stretch), this problem has been fixed in version 0.16.5-0.1.

For the unstable distribution (sid), this problem has been fixed in version 0.16.5-0.1.

We recommend that you upgrade your gajim packages.