CVE Vulnerabilities

CVE-2022-39835

Published: Sep 27, 2022 | Modified: Sep 28, 2022
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

An issue was discovered in Gajim through 1.4.7. The vulnerability allows attackers, via crafted XML stanzas, to correct messages that were not sent by them. The attacker needs to be part of the group chat or single chat. The fixed version is 1.5.0.

Affected Software

Name Vendor Start Version End Version
Gajim Gajim * 1.5.0 (excluding)
Gajim Ubuntu bionic *
Gajim Ubuntu kinetic *
Gajim Ubuntu lunar *
Gajim Ubuntu trusty *
Gajim Ubuntu upstream *
Gajim Ubuntu xenial *

References