CVE-2016-10027

CVE-2016-10027

Race condition in the XMPP library in Smack before 4.1.9, when the SecurityMode.required TLS setting has been set, allows man-in-the-middle attackers to bypass TLS protections and trigger use of cleartext for client authentication by stripping the "starttls" feature from a server response.

Source: CVE-2016-10027

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다