Input validation error in Gajim - CVE-2021-41055
Published: February 2, 2022
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can send a specially crafted XMPP Last Message Correction (XEP-0308) message in multi-user chat, where the message ID equals the correction ID and perform a denial of service (DoS) attack.
Affected software
python-nbxmpp (Debian package)
How to mitigate CVE-2021-41055
python-nbxmpp (Debian package) - update to 2.0.2-1+deb11u1