ArchLinux: 201706-4: gajim: information disclosure
Summary
Gajim through 0.16.7 unconditionally implements the "XEP-0146: Remote Controlling Clients" extension. This can be abused by malicious XMPP servers to, for example, extract plaintext from OTR encrypted sessions.
Resolution
Upgrade to 0.16.8-1.
# pacman -Syu "gajim>=0.16.8-1"
The problem has been fixed upstream in version 0.16.8.
References
https://dev.gajim.org/gajim/gajim/issues/8378 https://dev.gajim.org/gajim/gajim/commit/cb65cfc5aed9efe05208ebbb7fb2d41fcf7253cc https://security.archlinux.org/CVE-2016-1037
Workaround
None.