Bug 1041163 - (CVE-2016-10376) VUL-0: CVE-2016-10376: gajim: XEP-0146 extension can be abused by malicious XMPP servers
(CVE-2016-10376)
VUL-0: CVE-2016-10376: gajim: XEP-0146 extension can be abused by malicious ...
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other openSUSE 42.2
: P3 - Medium : Major
: ---
Assigned To: Alexei Sorokin
Security Team bot
https://smash.suse.de/issue/185980/
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2017-05-29 06:41 UTC by Johannes Segitz
Modified: 2017-06-11 19:51 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Johannes Segitz 2017-05-29 06:41:33 UTC
CVE-2016-10376

Gajim through 0.16.7 unconditionally implements the "XEP-0146: Remote
Controlling Clients" extension. This can be abused by malicious XMPP servers to,
for example, extract plaintext from OTR encrypted sessions.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-10376
http://seclists.org/oss-sec/2017/q2/341
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=863445
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-10376
https://dev.gajim.org/gajim/gajim/commit/cb65cfc5aed9efe05208ebbb7fb2d41fcf7253cc
https://mail.jabber.org/pipermail/standards/2016-August/031335.html
https://dev.gajim.org/gajim/gajim/issues/8378
Comment 1 Bernhard Wiedemann 2017-05-29 12:00:28 UTC
This is an autogenerated message for OBS integration:
This bug (1041163) was mentioned in
https://build.opensuse.org/request/show/498950 42.2 / gajim
Comment 2 Swamp Workflow Management 2017-06-08 16:10:11 UTC
openSUSE-SU-2017:1506-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 1041163
CVE References: CVE-2016-10376
Sources used:
openSUSE Leap 42.2 (src):    gajim-0.16.7-2.3.1
Comment 3 Alexei Sorokin 2017-06-11 19:51:30 UTC
Settled.