Bugzilla – Bug 1041163
VUL-0: CVE-2016-10376: gajim: XEP-0146 extension can be abused by malicious XMPP servers
Last modified: 2017-06-11 19:51:30 UTC
CVE-2016-10376 Gajim through 0.16.7 unconditionally implements the "XEP-0146: Remote Controlling Clients" extension. This can be abused by malicious XMPP servers to, for example, extract plaintext from OTR encrypted sessions. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-10376 http://seclists.org/oss-sec/2017/q2/341 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=863445 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-10376 https://dev.gajim.org/gajim/gajim/commit/cb65cfc5aed9efe05208ebbb7fb2d41fcf7253cc https://mail.jabber.org/pipermail/standards/2016-August/031335.html https://dev.gajim.org/gajim/gajim/issues/8378
This is an autogenerated message for OBS integration: This bug (1041163) was mentioned in https://build.opensuse.org/request/show/498950 42.2 / gajim
openSUSE-SU-2017:1506-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1041163 CVE References: CVE-2016-10376 Sources used: openSUSE Leap 42.2 (src): gajim-0.16.7-2.3.1
Settled.