Vulnerability CVE-2017-5591


Published: 2017-02-09

Description:
An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks. This CVE is for SleekXMPP up to 1.3.1 and Slixmpp all versions up to 1.2.3, as bundled in poezio (0.8 - 0.10) and other products.

See advisories in our WLB2 database:
Topic
Author
Date
Med.
Multiple XMPP Clients User Impersonation Vulnerability
Georg Lukas
10.02.2017

Type:

CWE-346

(Origin Validation Error)

CVSS2 => (AV:N/AC:M/Au:N/C:N/I:P/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4.3/10
2.9/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
None
Partial
None
Affected software
Slixmpp project -> Slixmpp 
Sleekxmpp project -> Sleekxmpp 
Poezio -> Poezio 

 References:
http://openwall.com/lists/oss-security/2017/02/09/29
http://www.securityfocus.com/bid/96166
https://github.com/poezio/slixmpp/commit/22664ee7b86c8e010f312b66d12590fb47160ad8
https://rt-solutions.de/en/2017/02/CVE-2017-5589_xmpp_carbons/
https://rt-solutions.de/wp-content/uploads/2017/02/CVE-2017-5589_xmpp_carbons.pdf

Copyright 2024, cxsecurity.com

 

Back to Top