The OTR plugin for Gajim sends information in cleartext when using XHTML, which allows remote attackers to obtain sensitive information via unspecified vectors.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://trac-plugins.gajim.org/changeset/c7c2e519ed63377bc943dd01c4661b0fe49321ae | permissions required |
http://www.openwall.com/lists/oss-security/2016/10/30/2 | third party advisory mailing list |
http://www.securityfocus.com/bid/94099 | vdb entry third party advisory |
https://dev.gajim.org/gajim/gajim-plugins/issues/145 | issue tracking patch |
http://www.openwall.com/lists/oss-security/2016/10/30/11 | third party advisory mailing list |