An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks. This CVE is for jappix 1.0.0 to 1.1.6.
References
Link | Resource |
---|---|
http://openwall.com/lists/oss-security/2017/02/09/29 | Exploit Mailing List Third Party Advisory |
http://www.securityfocus.com/bid/96176 | |
https://github.com/jappix/jappix/commit/ea6de7c65b80880bdf85df47c1a8a5d3d68491af | Patch |
https://rt-solutions.de/en/2017/02/CVE-2017-5589_xmpp_carbons/ | Exploit Technical Description Third Party Advisory |
https://rt-solutions.de/wp-content/uploads/2017/02/CVE-2017-5589_xmpp_carbons.pdf | Exploit Technical Description Third Party Advisory |
http://openwall.com/lists/oss-security/2017/02/09/29 | Exploit Mailing List Third Party Advisory |
http://www.securityfocus.com/bid/96176 | |
https://github.com/jappix/jappix/commit/ea6de7c65b80880bdf85df47c1a8a5d3d68491af | Patch |
https://rt-solutions.de/en/2017/02/CVE-2017-5589_xmpp_carbons/ | Exploit Technical Description Third Party Advisory |
https://rt-solutions.de/wp-content/uploads/2017/02/CVE-2017-5589_xmpp_carbons.pdf | Exploit Technical Description Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 03:27
Type | Values Removed | Values Added |
---|---|---|
References | () http://openwall.com/lists/oss-security/2017/02/09/29 - Exploit, Mailing List, Third Party Advisory | |
References | () http://www.securityfocus.com/bid/96176 - | |
References | () https://github.com/jappix/jappix/commit/ea6de7c65b80880bdf85df47c1a8a5d3d68491af - Patch | |
References | () https://rt-solutions.de/en/2017/02/CVE-2017-5589_xmpp_carbons/ - Exploit, Technical Description, Third Party Advisory | |
References | () https://rt-solutions.de/wp-content/uploads/2017/02/CVE-2017-5589_xmpp_carbons.pdf - Exploit, Technical Description, Third Party Advisory |
Information
Published : 2017-02-09 20:59
Updated : 2024-11-21 03:27
NVD link : CVE-2017-5602
Mitre link : CVE-2017-5602
CVE.ORG link : CVE-2017-5602
JSON object : View
Products Affected
jappix_project
- jappix