CVE-2016-10376
MEDIUMGajim < 0.16.7 - Cryptographic Issue
Title source: ruleDescription
Gajim through 0.16.7 unconditionally implements the "XEP-0146: Remote Controlling Clients" extension. This can be abused by malicious XMPP servers to, for example, extract plaintext from OTR encrypted sessions.
References (6)
Scores
CVSS v3
4.5
EPSS
0.0052
EPSS Percentile
66.6%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
Details
CWE
CWE-310
Status
published
Products (2)
gajim/gajim
< 0.16.7
n/a/n/a
Published
May 28, 2017
Tracked Since
Feb 18, 2026