CVE-2023-3434

Improper Input Validation in the hyperlink interpretation in Savoir-faire Linux's Jami (version 20222284) on Windows. This allows an attacker to send a custom HTML anchor tag to pass a string value to the Windows QRC Handler through the Jami messenger.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:savoirfairelinux:jami:20222284:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

26 Jul 2023, 14:05

Type Values Removed Values Added
References (MISC) https://blog.blacklanternsecurity.com/p/Jami-Local-Denial-Of-Service-and-QRC-Handler-Vulnerabilities - (MISC) https://blog.blacklanternsecurity.com/p/Jami-Local-Denial-Of-Service-and-QRC-Handler-Vulnerabilities - Broken Link
References (MISC) https://git.jami.net/savoirfairelinux/jami-client-qt/-/wikis/Changelog#nightly-january-10 - (MISC) https://git.jami.net/savoirfairelinux/jami-client-qt/-/wikis/Changelog#nightly-january-10 - Release Notes
References (MISC) https://review.jami.net/c/jami-client-qt/+/23569 - (MISC) https://review.jami.net/c/jami-client-qt/+/23569 - Patch
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
CWE NVD-CWE-noinfo
First Time Microsoft windows
Microsoft
Savoirfairelinux
Savoirfairelinux jami
CPE cpe:2.3:a:savoirfairelinux:jami:20222284:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

14 Jul 2023, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-07-14 13:15

Updated : 2024-02-28 20:33


NVD link : CVE-2023-3434

Mitre link : CVE-2023-3434

CVE.ORG link : CVE-2023-3434


JSON object : View

Products Affected

microsoft

  • windows

savoirfairelinux

  • jami
CWE
NVD-CWE-noinfo CWE-20

Improper Input Validation