Executive brief
Gajim is a popular open-source instant messaging client. A vulnerability in its Off-the-Record (OTR) encryption plugin causes private messages to be sent in plain text when formatted with XHTML. This allows unauthorized parties to intercept and read sensitive conversations that users believe are encrypted.
Technical details
An information disclosure vulnerability exists in the Gajim OTR plugin (gotr/otrmodule.py) due to improper handling of XHTML-IM formatted messages. When a user sends a message containing XHTML markup, the plugin fails to intercept and encrypt the XHTML body, transmitting it in cleartext alongside the encrypted OTR payload. A remote attacker or a malicious service provider can intercept these packets to read the original message content. The issue was addressed in changeset c7c2e519ed63377bc943dd01c4661b0fe49321ae.
Affected products
- Gajim Gajim OTR Plugin All versions prior to changeset c7c2e519ed63377bc943dd01c4661b0fe49321ae
Timeline
- 2016-10-30: disclosed: Vulnerability reported on oss-security mailing list.
- 2016-10-30: patched: Fix committed to the Gajim plugins repository.
- 2017-01-13: advisory: NVD published the CVE record.