Описание
Security update for python3-sleekxmpp
This update for python3-sleekxmpp fixes the following issues:
- Check the origin of roster pushes (2015-8688, 2016-9928, boo#1014976). Also see https://gultsch.de/gajim_roster_push_and_message_interception.html
- An error in legacyauth support was fixed
Список пакетов
openSUSE Leap 42.2
python3-sleekxmpp-1.3.1-3.1
Ссылки
- E-Mail link for openSUSE-SU-2017:0259-1
- SUSE Security Ratings
Описание
Gajim before 0.16.5 allows remote attackers to modify the roster and intercept messages via a crafted roster-push IQ stanza.
Затронутые продукты
openSUSE Leap 42.2:python3-sleekxmpp-1.3.1-3.1
Ссылки
- CVE-2015-8688
- SUSE Bug 1014976
- SUSE Bug 960668
Описание
MCabber before 1.0.4 is vulnerable to roster push attacks, which allows remote attackers to intercept communications, or add themselves as an entity on a 3rd party's roster as another user, which will also garner associated privileges, via crafted XMPP packets.
Затронутые продукты
openSUSE Leap 42.2:python3-sleekxmpp-1.3.1-3.1
Ссылки
- CVE-2016-9928
- SUSE Bug 1014976