Race condition in the XMPP library in Smack before 4.1.9, when the SecurityMode.required TLS setting has been set, allows man-in-the-middle attackers to bypass TLS protections and trigger use of cleartext for client authentication by stripping the "starttls" feature from a server response.
{
"unresolved_ranges": [
{
"extracted_events": [
{
"last_affected": "25"
}
],
"cpe": "cpe:2.3:o:fedoraproject:fedora:25:*:*:*:*:*:*:*",
"source": "CPE_FIELD"
}
]
}{
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "4.1.9"
}
],
"cpe": "cpe:2.3:a:igniterealtime:smack:*:*:*:*:*:*:*:*",
"source": "CPE_FIELD"
}