CVE-2023-3434 Information

Description

Improper Input Validation in the hyperlink interpretation in Savoir-faire Linux’s Jami (version 20222284) on Windows.

This allows an attacker to send a custom HTML anchor tag to pass a string value to the Windows QRC Handler through the Jami messenger.

Reference

https://review.jami.net/c/jami-client-qt/+/23569 https://git.jami.net/savoirfairelinux/jami-client-qt/-/wikis/Changelog#nightly-january-10 https://blog.blacklanternsecurity.com/p/Jami-Local-Denial-Of-Service-and-QRC-Handler-Vulnerabilities

Share on: