Skip to content

Upgrade sleekxmpp to 1.3.2#6773

Merged
fabaff merged 1 commit into
home-assistant:devfrom
fabaff:upgrade-SleekXMPP
Mar 24, 2017
Merged

Upgrade sleekxmpp to 1.3.2#6773
fabaff merged 1 commit into
home-assistant:devfrom
fabaff:upgrade-SleekXMPP

Conversation

@fabaff
Copy link
Copy Markdown
Member

@fabaff fabaff commented Mar 24, 2017

1.3.2

  • CVE-2017-5589+ Multiple XMPP Clients User Impersonation Vulnerability

Tested with the following configuration:

notify:
  - platform: xmpp
    name: jabber
    sender: sender@jabber.org
    password: !secret xmpp_password
    recipient: home@jabber.org

Message sent with "Call Service"

{"message": "The sun is {% if is_state('sun.sun', 'above_horizon') %}up{% else %}down{% endif %}!"}

@mention-bot
Copy link
Copy Markdown

@fabaff, thanks for your PR! By analyzing the history of the files in this pull request, we identified @balloob, @rmkraus and @pvizeli to be potential reviewers.

@fabaff fabaff merged commit 8d606f8 into home-assistant:dev Mar 24, 2017
@fabaff fabaff deleted the upgrade-SleekXMPP branch March 24, 2017 20:44
@thundergreen
Copy link
Copy Markdown

I get those error with following config:

  - name: thorsten
    platform: xmpp
    sender: home-assistant@xmpp.home
    password: home-assistant
    recipient: thorsten@emevth.no-ip.biz
    tls: false

ERROR MEssage:

17-04-04 10:44:07 ERROR (event_thread_0) [sleekxmpp.features.feature_mechanisms.mechanisms] No appropriate login method.
17-04-04 10:45:05 ERROR (event_thread_0) [sleekxmpp.features.feature_mechanisms.mechanisms] No appropriate login method.
17-04-04 10:45:07 ERROR (event_thread_0) [sleekxmpp.features.feature_mechanisms.mechanisms] No appropriate login method.
17-04-04 10:45:08 ERROR (event_thread_0) [sleekxmpp.features.feature_mechanisms.mechanisms] No appropriate login method.
17-04-04 10:45:09 ERROR (event_thread_0) [sleekxmpp.features.feature_mechanisms.mechanisms] No appropriate login method.
17-04-04 10:45:12 ERROR (read_thread) [sleekxmpp.xmlstream.xmlstream] Can not read from closed socket.
17-04-04 10:45:12 ERROR (read_thread) [sleekxmpp.xmlstream.xmlstream] Can not read from closed socket.
17-04-04 10:45:13 ERROR (read_thread) [sleekxmpp.xmlstream.xmlstream] Can not read from closed socket.

But message are delivered.

I am running my own jabber server :)

@fabaff fabaff mentioned this pull request Apr 6, 2017
@home-assistant home-assistant locked and limited conversation to collaborators Jul 17, 2017
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants