Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-10376

Опубликовано: 28 мая 2017
Источник: debian

Описание

Gajim through 0.16.7 unconditionally implements the "XEP-0146: Remote Controlling Clients" extension. This can be abused by malicious XMPP servers to, for example, extract plaintext from OTR encrypted sessions.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gajimfixed0.16.6-1.1package

Примечания

  • https://dev.gajim.org/gajim/gajim/commit/cb65cfc5aed9efe05208ebbb7fb2d41fcf7253cc

  • https://dev.gajim.org/gajim/gajim/issues/8378

Связанные уязвимости

CVSS3: 4.5
ubuntu
больше 8 лет назад

Gajim through 0.16.7 unconditionally implements the "XEP-0146: Remote Controlling Clients" extension. This can be abused by malicious XMPP servers to, for example, extract plaintext from OTR encrypted sessions.

CVSS3: 4.5
nvd
больше 8 лет назад

Gajim through 0.16.7 unconditionally implements the "XEP-0146: Remote Controlling Clients" extension. This can be abused by malicious XMPP servers to, for example, extract plaintext from OTR encrypted sessions.

suse-cvrf
больше 8 лет назад

Security update for gajim

CVSS3: 4.5
github
больше 3 лет назад

Gajim through 0.16.7 unconditionally implements the "XEP-0146: Remote Controlling Clients" extension. This can be abused by malicious XMPP servers to, for example, extract plaintext from OTR encrypted sessions.