← Back to team overview

desktop-packages team mailing list archive

[Bug 1381484] [NEW] Fails to connect to irc.slack.com with an SSL error

 

*** This bug is a security vulnerability ***

Public security bug reported:

slack.com is a chat service with optional IRC integration.  Since today
I can no longer connect to their IRC gateway using XChat-GNOME.  The
error is:

> * Nepavyko prisijungti. Klaida: (336130315) error:1408F10B:SSL routines:SSL3_GET_RECORD:wrong version number
> Ar tai tikrai SSL šifravimą palaikantis serveris ir prievadas?

which, translated from lt_LT, means

> * Cannot connect.  Error: (336130315) error:1408F10B:SSL routines:SSL3_GET_RECORD:wrong version number
> Does the server/port really support SSL?

I think this is part of the fallout of CVE-2014-3566 (aka POODLE).
XChat-GNOME is trying to use the insecure SSL protocol version 3, and
Slack, reasonably enough, rejects that.

ProblemType: Bug
DistroRelease: Ubuntu 14.04
Package: xchat-gnome 1:0.30.0~git20131003.d20b8d+really20110821-0.2ubuntu12
ProcVersionSignature: Ubuntu 3.13.0-37.64-generic 3.13.11.7
Uname: Linux 3.13.0-37-generic x86_64
ApportVersion: 2.14.1-0ubuntu3.5
Architecture: amd64
CurrentDesktop: GNOME
Date: Wed Oct 15 14:50:57 2014
EcryptfsInUse: Yes
InstallationDate: Installed on 2012-07-25 (811 days ago)
InstallationMedia: Ubuntu 12.04 LTS "Precise Pangolin" - Release amd64 (20120425)
SourcePackage: xchat-gnome
UpgradeStatus: Upgraded to trusty on 2014-04-18 (180 days ago)

** Affects: xchat-gnome (Ubuntu)
     Importance: Undecided
         Status: New


** Tags: amd64 apport-bug gnome3-ppa third-party-packages trusty

** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2014-3566

** Information type changed from Private Security to Public Security

-- 
You received this bug notification because you are a member of Desktop
Packages, which is subscribed to xchat-gnome in Ubuntu.
https://bugs.launchpad.net/bugs/1381484

Title:
  Fails to connect to irc.slack.com with an SSL error

Status in “xchat-gnome” package in Ubuntu:
  New

Bug description:
  slack.com is a chat service with optional IRC integration.  Since
  today I can no longer connect to their IRC gateway using XChat-GNOME.
  The error is:

  > * Nepavyko prisijungti. Klaida: (336130315) error:1408F10B:SSL routines:SSL3_GET_RECORD:wrong version number
  > Ar tai tikrai SSL šifravimą palaikantis serveris ir prievadas?

  which, translated from lt_LT, means

  > * Cannot connect.  Error: (336130315) error:1408F10B:SSL routines:SSL3_GET_RECORD:wrong version number
  > Does the server/port really support SSL?

  I think this is part of the fallout of CVE-2014-3566 (aka POODLE).
  XChat-GNOME is trying to use the insecure SSL protocol version 3, and
  Slack, reasonably enough, rejects that.

  ProblemType: Bug
  DistroRelease: Ubuntu 14.04
  Package: xchat-gnome 1:0.30.0~git20131003.d20b8d+really20110821-0.2ubuntu12
  ProcVersionSignature: Ubuntu 3.13.0-37.64-generic 3.13.11.7
  Uname: Linux 3.13.0-37-generic x86_64
  ApportVersion: 2.14.1-0ubuntu3.5
  Architecture: amd64
  CurrentDesktop: GNOME
  Date: Wed Oct 15 14:50:57 2014
  EcryptfsInUse: Yes
  InstallationDate: Installed on 2012-07-25 (811 days ago)
  InstallationMedia: Ubuntu 12.04 LTS "Precise Pangolin" - Release amd64 (20120425)
  SourcePackage: xchat-gnome
  UpgradeStatus: Upgraded to trusty on 2014-04-18 (180 days ago)

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/xchat-gnome/+bug/1381484/+subscriptions


Follow ups

References