Security Advisory

CVE-2016-10376

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2017-05-28 00:00:00
Last updated 2024-08-06 03:21:51
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Gajim through 0.16.7 unconditionally implements the "XEP-0146: Remote Controlling Clients" extension. This can be abused by malicious XMPP servers to, for example, extract plaintext from OTR encrypted sessions.