First published: Thu Jan 12 2017(Updated: )
Race condition in the XMPP library in Smack before 4.1.9, when the SecurityMode.required TLS setting has been set, allows man-in-the-middle attackers to bypass TLS protections and trigger use of cleartext for client authentication by stripping the "starttls" feature from a server response.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Igniterealtime Smack | <4.1.9 | |
Fedoraproject Fedora | =25 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.