ejabberd 'starttls_required' Encryption Security Weakness
BID:70415
Info
ejabberd 'starttls_required' Encryption Security Weakness
| Bugtraq ID: | 70415 |
| Class: | Design Error |
| CVE: |
CVE-2014-8760 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 13 2014 12:00AM |
| Updated: | Oct 29 2014 12:59AM |
| Credit: | Mathias Ertl |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
ejabberd 'starttls_required' Encryption Security Weakness
ejabberd is prone to a security weakness that may allow attackers to obtain sensitive information.
Successfully exploiting this issue may allow attackers to view encrypted data and obtain sensitive information. This may lead to other attacks.
ejabberd is prone to a security weakness that may allow attackers to obtain sensitive information.
Successfully exploiting this issue may allow attackers to view encrypted data and obtain sensitive information. This may lead to other attacks.
Exploit / POC
ejabberd 'starttls_required' Encryption Security Weakness
An attacker can exploit this issue using readily available tools.
An attacker can exploit this issue using readily available tools.
Solution / Fix
ejabberd 'starttls_required' Encryption Security Weakness
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.