Groundhog Day for denying authorization to Yahoo! Add

Bug #594436 reported by Stephen Gornick
264
This bug affects 2 people
Affects Status Importance Assigned to Milestone
telepathy-haze (Ubuntu)
Invalid
Undecided
Unassigned

Bug Description

Binary package hint: empathy

On startup of Empathy the icon in the notification panel is green, showing me that a user wishes for me to authorize them. They are a Yahoo! IM user. If I click on No, that I do not wish to authorize them, the icon in the notification panel changes from green to white and the request that I denied no longer shows.

However then when I quit Empathy and restart it, that previously denied request shows up once again, just like it did the first time. I again answer No to deny, and it disappears until the next restart.

The only way was able to permanently get the request to go away, was to accept the request, and then from the list of authorized contacts, Remove the offending contact.

Ubuntu 10.04 x86_64
Empathy 2.30.1

Revision history for this message
Karsten W. Rohrbach (byteborg) wrote :

I can second this behaviour in two installations (lucid amd64)

Revision history for this message
Karsten W. Rohrbach (byteborg) wrote :

Should be handled as security issue, since Joe User would simply add bogus unknown contacts (spammers et al.) and remove them from his roster. This results in unwanted information disclosure to untrusted third parties.

security vulnerability: no → yes
Revision history for this message
Omer Akram (om26er) wrote :

thanks for the bug report. this particular bug has already been reported but feel free to report any other bugs you may find.

affects: empathy (Ubuntu) → telepathy-haze (Ubuntu)
Changed in telepathy-haze (Ubuntu):
status: New → Invalid
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.