Gajim before 0.16.5 allows remote attackers to modify the roster and intercept messages via a crafted roster-push IQ stanza.
CVSS Details
- CVSS 3.1 Base Score: 5.4
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade gajim | Feb 25, 2016 | Jan 15, 2016 |
| Suse | — | Upgrade python3-sleekxmppUpgrade mcabberUpgrade mcabber-develUpgrade mcabber-debuginfoUpgrade gajim-langUpgrade mcabber-debugsourceUpgrade gajim | Feb 2, 2016 | Jan 13, 2016 |
| Ubuntu | — | Upgrade gajim | Nov 19, 2024 | Jan 15, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub