Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Fedora 25: Critical Update For Smack TLS Bypass Vulnerability

fedora
Calendar Grey December 29, 2016
Dist Fedora Esm H88
The latest Fedora 25 Smack update resolves a TLS SecurityMode.required bypass vulnerability, enhancing security by enforcing stricter TLS connection validation to prevent attacks
fix for "TLS SecurityMode.required bypass via StripTLS attack" (rhbz#1406703,1406704)

Summary

Smack is an Open Source XMPP (Jabber) client library for instant

messaging and presence. A pure Java library, it can be embedded

into your applications to create anything from a full XMPP client

to simple XMPP integrations such as sending notification messages and

presence-enabling devices.

Update Information:

fix for "TLS SecurityMode.required bypass via StripTLS attack" (rhbz#1406703,1406704)

Change Log

References


[ 1 ] Bug #1406703 - CVE-2016-10027 smack: TLS SecurityMode.required bypass via StripTLS attack https://bugzilla.redhat.com/show_bug.cgi?id=1406703

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade smack' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
critical
Lowest
Low
Medium
High
Critical

Name: smack
Product: Fedora 25
Version: 4.1.5
Release: 3.fc25
Summary: Open Source XMPP (Jabber) client library

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here