Vulnerability in message carbons allows forging sender ids, see: https://rt-solutions.de/en/2017/02/CVE-2017-5589_xmpp_carbons/ Fixed in mcabber 1.0.5. This affects a lot of clients, but most of them aren't in Gentoo, we should go through them and check all of them.
mcabber 1.0.5 is in portage now: https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=cb5ddb9eeebd7bb2a60f778e6670842ae0de17b7 @arches, please test and mark stable: =net-im/mcabber-1.0.5 thanks!
amd64 stable
x86 stable. Maintainer(s), please cleanup. Security, please vote.
GLSA Vote: No @ Maintainer(s): Please cleanup and drop =net-im/mcabber-1.0.4!
Tree is clean: https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=39626bfcaf6ffcd0cc19b76fb8654312e8aa23cf