CVE-2016-10027
published 2017-01-12CVE-2016-10027: Race condition in the XMPP library in Smack before 4.1.9, when the SecurityMode.required TLS setting has been set, allows man-in-the-middle attackers to bypass…
PriorityP432medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
1.52%
71.7th percentile
Race condition in the XMPP library in Smack before 4.1.9, when the SecurityMode.required TLS setting has been set, allows man-in-the-middle attackers to bypass TLS protections and trigger use of cleartext for client authentication by stripping the "starttls" feature from a server response.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fedoraproject | fedora | — | — |
| igniterealtime | smack | < 4.1.9 | 4.1.9 |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
smack: TLS SecurityMode.required bypass via StripTLS attack
vendor_redhat·2016-11-12·CVSS 5.9
CVE-2016-10027 [MEDIUM] smack: TLS SecurityMode.required bypass via StripTLS attack
smack: TLS SecurityMode.required bypass via StripTLS attack
Race condition in the XMPP library in Smack before 4.1.9, when the SecurityMode.required TLS setting has been set, allows man-in-the-middle attackers to bypass TLS protections and trigger use of cleartext for client authentication by stripping the "starttls" feature from a server response.
Package: smack (Red Hat JBoss BRMS 5) - Will not fix
Package: camel (Red Hat JBoss Fuse 6) - Will not fix
OSV
Smack allows the bypass of TLS protections
osv·2022-05-13
CVE-2016-10027 [MEDIUM] Smack allows the bypass of TLS protections
Smack allows the bypass of TLS protections
Race condition in the XMPP library in Smack before 4.1.9, when the SecurityMode.required TLS setting has been set, allows man-in-the-middle attackers to bypass TLS protections and trigger use of cleartext for client authentication by stripping the "starttls" feature from a server response.
GHSA
Smack allows the bypass of TLS protections
ghsa·2022-05-13
CVE-2016-10027 [MEDIUM] CWE-362 Smack allows the bypass of TLS protections
Smack allows the bypass of TLS protections
Race condition in the XMPP library in Smack before 4.1.9, when the SecurityMode.required TLS setting has been set, allows man-in-the-middle attackers to bypass TLS protections and trigger use of cleartext for client authentication by stripping the "starttls" feature from a server response.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-10027 smack: TLS SecurityMode.required bypass via StripTLS attack [fedora-all]
bugzilla·2016-12-21·CVSS 5.9
CVE-2016-10027 [MEDIUM] CVE-2016-10027 smack: TLS SecurityMode.required bypass via StripTLS attack [fedora-all]
CVE-2016-10027 smack: TLS SecurityMode.required bypass via StripTLS attack [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported ve
Bugzilla
CVE-2016-10027 smack: TLS SecurityMode.required bypass via StripTLS attack
bugzilla·2016-12-21·CVSS 5.9
CVE-2016-10027 [MEDIUM] CVE-2016-10027 smack: TLS SecurityMode.required bypass via StripTLS attack
CVE-2016-10027 smack: TLS SecurityMode.required bypass via StripTLS attack
A vulnerability in the Smack XMPP library was reported where the security of
the TLS connection is not always enforced. By stripping the "starttls"
feature from the server response with a man-in-the-middle tool, an attacker
can force the client to authenticate in clear text even if the
"SecurityMode.required" TLS setting has been set.
References:
http://seclists.org/oss-sec/2016/q4/716
https://community.igniterealtime.org/blogs/ignite/2016/11/22/smack-security-advisory-2016-11-22
Upstream bug:
https://issues.igniterealtime.org/browse/SMACK-739
Upstream patches:
https://github.com/igniterealtime/Smack/commit/059ee99ba0d5ff7758829acf5a9aeede09ec820b
https://github.com/igniterealtime/Smack/commit/a9d5cd4a611f471
http://www.openwall.com/lists/oss-security/2016/12/22/12http://www.securityfocus.com/bid/95129https://community.igniterealtime.org/blogs/ignite/2016/11/22/smack-security-advisory-2016-11-22https://github.com/igniterealtime/Smack/commit/059ee99ba0d5ff7758829acf5a9aeede09ec820bhttps://github.com/igniterealtime/Smack/commit/a9d5cd4a611f47123f9561bc5a81a4555fe7cb04https://issues.igniterealtime.org/projects/SMACK/issues/SMACK-739https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/J4WXAZ4JVJXHMEDDXJVWJHPVBF5QCTZF/http://www.openwall.com/lists/oss-security/2016/12/22/12http://www.securityfocus.com/bid/95129https://community.igniterealtime.org/blogs/ignite/2016/11/22/smack-security-advisory-2016-11-22https://github.com/igniterealtime/Smack/commit/059ee99ba0d5ff7758829acf5a9aeede09ec820bhttps://github.com/igniterealtime/Smack/commit/a9d5cd4a611f47123f9561bc5a81a4555fe7cb04https://issues.igniterealtime.org/projects/SMACK/issues/SMACK-739https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/J4WXAZ4JVJXHMEDDXJVWJHPVBF5QCTZF/
2017-01-12
Published