CVE
- Id
- 87520
- CVE No.
- CVE-2016-10027
- Status
- Candidate
- Description
- Race condition in the XMPP library in Smack before 4.1.9, when the SecurityMode.required TLS setting has been set, allows man-in-the-middle attackers to bypass TLS protections and trigger use of cleartext for client authentication by stripping the "starttls" feature from a server response.
- Phase
- Assigned (20161222)
- Votes
- None (candidate not yet proposed)
- Comments