5.8
CVE-2015-8688
- EPSS 1.72%
- Veröffentlicht 15.01.2016 19:59:03
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Gajim before 0.16.5 allows remote attackers to modify the roster and intercept messages via a crafted roster-push IQ stanza.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.72% | 0.745 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.4 | 2.8 | 2.5 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
|
| nvd@nist.gov | 5.8 | 8.6 | 4.9 |
AV:N/AC:M/Au:N/C:P/I:P/A:N
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
http://gultsch.de/gajim_roster_push_and_message_interception.html
http://lists.fedoraproject.org/pipermail/package-announce/2016-January/175503.html
http://lists.fedoraproject.org/pipermail/package-announce/2016-January/175526.html
http://lists.opensuse.org/opensuse-updates/2016-01/msg00027.html
http://www.debian.org/security/2016/dsa-3492
https://hg.gajim.org/gajim/file/gajim-0.16.5/ChangeLog