telepathy-idle before 0.1.15 does not verify (1) that the issuer is a trusted CA, (2) that the server hostname matches a domain name in the subject's Common Name (CN), or (3) the expiration date of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
| Software | From | Fixed in |
|---|---|---|
| canonical / telepathy-idle | - | 0.1.14.1.x |
| canonical / ubuntu_linux | 13.04 | 13.04.x |
| canonical / telepathy-idle | 0.1.12.1 | 0.1.12.1.x |
| canonical / telepathy-idle | 0.1.11.1 | 0.1.11.1.x |
| canonical / telepathy-idle | 0.1.10.1 | 0.1.10.1.x |
| canonical / ubuntu_linux | 12.10 | 12.10.x |
| canonical / telepathy-idle | 0.1.11.2 | 0.1.11.2.x |
| canonical / ubuntu_linux | 12.04 | 12.04.x |
| canonical / telepathy-idle | 0.1.14 | 0.1.14.x |