Vulnerability Description
Gajim 1.2.x and 1.3.x before 1.3.3 allows remote attackers to cause a denial of service (crash) via a crafted XMPP Last Message Correction (XEP-0308) message in multi-user chat, where the message ID equals the correction ID.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gajim | Gajim | >= 1.2.0, < 1.3.3 |
References
- https://dev.gajim.org/gajim/gajim/-/issues/10638ExploitIssue TrackingVendor Advisory
- https://dev.gajim.org/gajim/gajim/-/tags/gajim-1.3.3Vendor Advisory
- https://dev.gajim.org/gajim/gajim/-/issues/10638ExploitIssue TrackingVendor Advisory
- https://dev.gajim.org/gajim/gajim/-/tags/gajim-1.3.3Vendor Advisory
FAQ
What is CVE-2021-41055?
CVE-2021-41055 is a vulnerability with a CVSS score of 7.5 (HIGH). Gajim 1.2.x and 1.3.x before 1.3.3 allows remote attackers to cause a denial of service (crash) via a crafted XMPP Last Message Correction (XEP-0308) message in multi-user chat, where the message ID e...
How severe is CVE-2021-41055?
CVE-2021-41055 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-41055?
Check the references section above for vendor advisories and patch information. Affected products include: Gajim Gajim.