Openwall GNU/*/Linux - a small security-enhanced Linux distro for servers
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Tue, 14 Oct 2014 12:39:48 +1100
From: Michael Samuel <mik@...net.net>
To: oss-security@...ts.openwall.com
Subject: Re: CVE request: ejabberd compression allows
 cirucumvention of encryption despite starttls_required

On 14 October 2014 00:09, Hanno Böck <hanno@...eck.de> wrote:
> I think this deserves a CVE:
> http://mail.jabber.org/pipermail/operators/2014-October/002438.html

If a client is willing to do that, then an attacker can simply force downgrade
the client and connect to the server using TLS. (Assuming client
certificates aren't in use)

Regards,
  Michael

Powered by blists - more mailing lists

Your e-mail address:

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Powered by Openwall GNU/*/Linux - Powered by OpenVZ