Vulnerability Bulletins

DSA-3943 gajim - security update

   
Affected software Debian
 
Gajim, a GTK+-based XMPP/Jabber client, unconditionally implements the"XEP-0146: Remote Controlling Clients" extension, allowing a maliciousXMPP server to trigger commands to leak private conversations fromencrypted sessions. With this update XEP-0146 support has been disabledby default and made opt-in via the remote_commands option.

More info:

https://www.debian.org/security/2017/dsa-3943