USN-1250-1: Empathy vulnerabilities
28 October 2011
Empathy could be made to run programs or display webpages via specially crafted nicknames.
Releases
Packages
- empathy - GNOME multi-protocol chat and call client
Details
It was discovered that a cross-site scripting (XSS) vulnerability in
the Adium theme allows remote attackers to inject arbitrary javascript
or HTML via a crafted nickname in XMPP group conversations.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 11.10
Ubuntu 11.04
Ubuntu 10.10
Ubuntu 10.04
After a standard system update you need to restart your session to
make all the necessary changes.