A vulnerability in the Smack XMPP library was reported where the security of
the TLS connection is not always enforced. By stripping the "starttls"
feature from the server response with a man-in-the-middle tool, an attacker
can force the client to authenticate in clear text even if the
"SecurityMode.required" TLS setting has been set.
Created smack tracking bugs for this issue:
Affects: fedora-all [bug 1406704]