CVE-2016-10027

Severity CVSS v4.0:
Pending analysis
Type:
CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
Publication date:
12/01/2017
Last modified:
20/04/2025

Description

Race condition in the XMPP library in Smack before 4.1.9, when the SecurityMode.required TLS setting has been set, allows man-in-the-middle attackers to bypass TLS protections and trigger use of cleartext for client authentication by stripping the "starttls" feature from a server response.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:igniterealtime:smack:*:*:*:*:*:*:*:* 4.1.9 (excluding)
cpe:2.3:o:fedoraproject:fedora:25:*:*:*:*:*:*:*