CVE-2021-41055 - log back

CVE-2021-41055 edited at 11 Oct 2021 09:21:54
Severity
- Unknown
+ Medium
Remote
- Unknown
+ Remote
Type
- Unknown
+ Denial of service
Description
+ Gajim 1.2.x and 1.3.x before 1.3.3 allows remote attackers to cause a denial of service (crash) via a crafted XMPP Last Message Correction (XEP-0308) message in multi-user chat, where the message ID equals the correction ID.
References
+ https://dev.gajim.org/gajim/gajim/-/issues/10638
+ https://dev.gajim.org/gajim/python-nbxmpp/-/commit/ce8191222c6602c65b414ec869ec2c66e368704f
+ https://dev.gajim.org/gajim/gajim/-/commit/02b8bcf4c69673f7808d7101586c9d78c2907d17
Notes
CVE-2021-41055 created at 11 Oct 2021 09:19:28