3.5
CVSSv2

CVE-2016-10376

Published: 28/05/2017 Updated: 06/11/2017
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 4.5 | Impact Score: 3.6 | Exploitability Score: 0.9
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:P/I:N/A:N

Vulnerability Summary

Gajim up to and including 0.16.7 unconditionally implements the "XEP-0146: Remote Controlling Clients" extension. This can be abused by malicious XMPP servers to, for example, extract plaintext from OTR encrypted sessions.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gajim gajim

Vendor Advisories

Debian Bug report logs - #863445 gajim: CVE-2016-10376: possible to remote extract plain-text from encrypted sessions Package: gajim; Maintainer for gajim is Debian XMPP Maintainers <pkg-xmpp-devel@listsaliothdebianorg>; Source for gajim is src:gajim (PTS, buildd, popcon) Reported by: "W Martin Borgert" <debacle@debia ...