CVE-2016-10027
12.01.2017, 23:59
Race condition in the XMPP library in Smack before 4.1.9, when the SecurityMode.required TLS setting has been set, allows man-in-the-middle attackers to bypass TLS protections and trigger use of cleartext for client authentication by stripping the "starttls" feature from a server response.
Vendor | Product | Version |
---|---|---|
igniterealtime | smack | 𝑥 < 4.1.9 |
𝑥
= Vulnerable software versions
References