It was found that gajim doesn’t verify the origin of roster pushes thus allowing third parties to modify the roster. External reference: http://gultsch.de/gajim_roster_push_and_message_interception.html Upstream patch: https://trac.gajim.org/changeset/af78b7c068904d78c5dfb802826aae99f26a8947/
Created gajim tracking bugs for this issue: Affects: fedora-all [bug 1295476] Affects: epel-all [bug 1295477]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.