Gajim before 0.16.5 allows remote attackers to modify the roster and intercept messages via a crafted roster-push IQ stanza.
CVSS Details
- CVSS 3.1 Base Score: 5.4
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade gajim | Feb 25, 2016 | Jan 15, 2016 |
| Suse | — | Upgrade mcabber-debugsourceUpgrade gajimUpgrade gajim-langUpgrade python3-sleekxmppUpgrade mcabber-debuginfoUpgrade mcabber-develUpgrade mcabber | Feb 2, 2016 | Jan 13, 2016 |
| Ubuntu | — | Upgrade gajim | Nov 19, 2024 | Jan 15, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub