Vulnerability Bulletins |
DSA-3943 gajim - security update |
|
| Affected software | Debian |
|
Gajim, a GTK+-based XMPP/Jabber client, unconditionally implements the"XEP-0146: Remote Controlling Clients" extension, allowing a maliciousXMPP server to trigger commands to leak private conversations fromencrypted sessions. With this update XEP-0146 support has been disabledby default and made opt-in via the remote_commands option. More info: https://www.debian.org/security/2017/dsa-3943 |
|






