Gajim 1.2.x and 1.3.x before 1.3.3 allows remote attackers to cause a denial of service (crash) via a crafted XMPP Last Message Correction (XEP-0308) message in multi-user chat, where the message ID equals the correction ID.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Gajim | Gajim | 1.2.0 (including) | 1.3.3 (excluding) |
Python-nbxmpp | Ubuntu | esm-apps/xenial | * |
Python-nbxmpp | Ubuntu | hirsute | * |
Python-nbxmpp | Ubuntu | trusty | * |
Python-nbxmpp | Ubuntu | upstream | * |
Python-nbxmpp | Ubuntu | xenial | * |