PatchSiren

Otr CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Otr CVE published 2017-01-13

CVE-2016-9107

CVE-2016-9107 is an information-disclosure issue in the OTR plugin for Gajim. When XHTML is used, the plugin can send information in cleartext, which can expose sensitive data to a remote attacker. NVD rates the issue HIGH, with a network-reachable attack path and no privileges or user interaction required.