CVE Vulnerabilities

CVE-2016-10376

Published: May 28, 2017 | Modified: Nov 06, 2017
CVSS 3.x
4.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
CVSS 2.x
3.5 LOW
AV:N/AC:M/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Gajim through 0.16.7 unconditionally implements the XEP-0146: Remote Controlling Clients extension. This can be abused by malicious XMPP servers to, for example, extract plaintext from OTR encrypted sessions.

Affected Software

Name Vendor Start Version End Version
Gajim Gajim * 0.16.7 (including)

References