CVE-2016-10027: Race Condition
Published Jan 12, 2017
·Updated
Race condition in the XMPP library in Smack before 4.1.9, when the SecurityMode.required TLS setting has been set, allows man-in-the-middle attackers to bypass TLS protections and trigger use of cleartext for client authentication by stripping the "starttls" feature from a server response.
Affected Software
3 affected componentsFixes available
igniterealtime Smack<4.1.9
Fedoraproject Fedora=25
maven/org.igniterealtime.smack:smack-core<4.1.9
4.1.9
Remediation
Patch Available
Event History
Jan 12, 2017
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Data Sourced
via NVD·11:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
May 13, 2022
Advisory Published
via GitHub·01:11 AM
Frequently Asked Questions
1
What is the severity of CVE-2016-10027?
CVE-2016-10027 is classified as a medium severity vulnerability due to its potential to allow man-in-the-middle attacks.
2
How do I fix CVE-2016-10027?
To fix CVE-2016-10027, upgrade the Smack library to version 4.1.9 or later.
3
Which versions of Smack are affected by CVE-2016-10027?
CVE-2016-10027 affects all Smack versions prior to 4.1.9.
4
What type of attack does CVE-2016-10027 allow?
CVE-2016-10027 allows man-in-the-middle attackers to bypass TLS protections.
5
Is Fedora 25 affected by CVE-2016-10027?
Yes, Fedora 25 is affected by CVE-2016-10027 if it uses a vulnerable version of the Smack library.