CVE-2023-3434 – QRC Handler without Input Validation in Jami
https://notcve.org/view.php?id=CVE-2023-3434
Improper Input Validation in the hyperlink interpretation in Savoir-faire Linux's Jami (version 20222284) on Windows. This allows an attacker to send a custom HTML anchor tag to pass a string value to the Windows QRC Handler through the Jami messenger. • https://blog.blacklanternsecurity.com/p/Jami-Local-Denial-Of-Service-and-QRC-Handler-Vulnerabilities https://git.jami.net/savoirfairelinux/jami-client-qt/-/wikis/Changelog#nightly-january-10 https://review.jami.net/c/jami-client-qt/+/23569 • CWE-20: Improper Input Validation •
CVE-2023-3433 – Local Denial of Service in Jami
https://notcve.org/view.php?id=CVE-2023-3433
The "nickname" field within Savoir-faire Linux's Jami application is susceptible to a failed state when a user inserts special characters into the field. When present, these special characters, make it so the application cannot create the signature for the user and results in a local denial of service to the application. • https://blog.blacklanternsecurity.com/p/Jami-Local-Denial-Of-Service-and-QRC-Handler-Vulnerabilities https://git.jami.net/savoirfairelinux/jami-client-qt/-/wikis/Changelog#nightly-january-10 https://review.jami.net/c/jami-daemon/+/23575 • CWE-20: Improper Input Validation •