Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-10027

Опубликовано: 12 янв. 2017
Источник: debian
EPSS Низкий

Описание

Race condition in the XMPP library in Smack before 4.1.9, when the SecurityMode.required TLS setting has been set, allows man-in-the-middle attackers to bypass TLS protections and trigger use of cleartext for client authentication by stripping the "starttls" feature from a server response.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libsmack-javaitppackage

EPSS

Процентиль: 59%
0.00388
Низкий

Связанные уязвимости

CVSS3: 7.5
redhat
около 9 лет назад

Race condition in the XMPP library in Smack before 4.1.9, when the SecurityMode.required TLS setting has been set, allows man-in-the-middle attackers to bypass TLS protections and trigger use of cleartext for client authentication by stripping the "starttls" feature from a server response.

CVSS3: 5.9
nvd
около 9 лет назад

Race condition in the XMPP library in Smack before 4.1.9, when the SecurityMode.required TLS setting has been set, allows man-in-the-middle attackers to bypass TLS protections and trigger use of cleartext for client authentication by stripping the "starttls" feature from a server response.

CVSS3: 5.9
github
больше 3 лет назад

Smack allows the bypass of TLS protections

EPSS

Процентиль: 59%
0.00388
Низкий