CVE Vulnerabilities

CVE-2016-10376

Published: May 28, 2017 | Modified: Nov 06, 2017
CVSS 3.x
4.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
CVSS 2.x
3.5 LOW
AV:N/AC:M/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Gajim through 0.16.7 unconditionally implements the XEP-0146: Remote Controlling Clients extension. This can be abused by malicious XMPP servers to, for example, extract plaintext from OTR encrypted sessions.

Affected Software

Name Vendor Start Version End Version
Gajim Gajim * 0.16.7 (including)
Gajim Ubuntu artful *
Gajim Ubuntu esm-apps/xenial *
Gajim Ubuntu trusty *
Gajim Ubuntu upstream *
Gajim Ubuntu xenial *
Gajim Ubuntu yakkety *
Gajim Ubuntu zesty *

References