445
VMScore

CVE-2021-41055

Published: 11/10/2021 Updated: 19/10/2021
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Gajim 1.2.x and 1.3.x prior to 1.3.3 allows remote malicious users to cause a denial of service (crash) via a crafted XMPP Last Message Correction (XEP-0308) message in multi-user chat, where the message ID equals the correction ID.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gajim gajim

Vendor Advisories

It was discovered that missing input sanitising in python-nbxmpp, a Jabber/XMPP Python library, could result in denial of service in clients based on it (such as Gajim) The oldstable distribution (buster) is not affected For the stable distribution (bullseye), this problem has been fixed in version 202-1+deb11u1 We recommend that you upgrade y ...
Gajim 12x and 13x before 133 allows remote attackers to cause a denial of service (crash) via a crafted XMPP Last Message Correction (XEP-0308) message in multi-user chat, where the message ID equals the correction ID ...