Mercurial > ~mikael > mcabber > hg
comparison mcabber/mcabber/xmpp_iq.h @ 2283:6e1ead98930d
Check origin of roster pushes
MCabber is vulnerable to roster push attacks as described by Daniel Gultsch
at https://gultsch.de/gajim_roster_push_and_message_interception.html.
This patch should fix the problem by checking the sender of the iq:roster
stanzas.
Thanks to Sam Whited for the report.
author | Mikael Berthe <mikael@lilotux.net> |
---|---|
date | Mon, 21 Nov 2016 20:35:28 +0100 |
parents | e6d355e50d7a |
children |
comparison
equal
deleted
inserted
replaced
2275:3d6986784dae | 2283:6e1ead98930d |
---|