An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks. This CVE is for jappix 1.0.0 to 1.1.6.
References
Link | Resource |
---|---|
https://rt-solutions.de/wp-content/uploads/2017/02/CVE-2017-5589_xmpp_carbons.pdf | Exploit Technical Description Third Party Advisory |
https://rt-solutions.de/en/2017/02/CVE-2017-5589_xmpp_carbons/ | Exploit Technical Description Third Party Advisory |
https://github.com/jappix/jappix/commit/ea6de7c65b80880bdf85df47c1a8a5d3d68491af | Patch |
http://openwall.com/lists/oss-security/2017/02/09/29 | Exploit Mailing List Third Party Advisory |
http://www.securityfocus.com/bid/96176 |
Configurations
Configuration 1 (hide)
|
Information
Published : 2017-02-09 12:59
Updated : 2017-02-28 18:59
NVD link : CVE-2017-5602
Mitre link : CVE-2017-5602
JSON object : View
Products Affected
jappix_project
- jappix