It was discovered that MCabber versions 1.0.3 and before are vulnerable to an attack identical to Gajim's CVE-2015-8688 that can lead to a malicious actor MITMing a conversation, or adding themselves as an entity on a third parties roster (thereby granting themselves the associated privileges). Upstream patch: https://bitbucket.org/McKael/mcabber-crew/commits/6e1ead98930d7dd0a520ad17c720ae4908429033/raw References: https://gultsch.de/gajim_roster_push_and_message_interception.html http://seclists.org/oss-sec/2016/q4/653
Created mcabber tracking bugs for this issue: Affects: fedora-all [bug 1403792]
mcabber 1.0.4 has already arrived to stable in F23, F24, F25, rawhide