Gajim through 0.16.7 unconditionally implements the XEP-0146: Remote Controlling Clients extension. This can be abused by malicious XMPP servers to, for example, extract plaintext from OTR encrypted sessions.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Gajim | Gajim | * | 0.16.7 (including) |
Gajim | Ubuntu | artful | * |
Gajim | Ubuntu | esm-apps/xenial | * |
Gajim | Ubuntu | trusty | * |
Gajim | Ubuntu | upstream | * |
Gajim | Ubuntu | xenial | * |
Gajim | Ubuntu | yakkety | * |
Gajim | Ubuntu | zesty | * |