An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks. This CVE is for jappix 1.0.0 to 1.1.6.
References
Link | Resource |
---|---|
http://openwall.com/lists/oss-security/2017/02/09/29 | Exploit Mailing List Third Party Advisory |
http://www.securityfocus.com/bid/96176 | |
https://github.com/jappix/jappix/commit/ea6de7c65b80880bdf85df47c1a8a5d3d68491af | Patch |
https://rt-solutions.de/en/2017/02/CVE-2017-5589_xmpp_carbons/ | Exploit Technical Description Third Party Advisory |
https://rt-solutions.de/wp-content/uploads/2017/02/CVE-2017-5589_xmpp_carbons.pdf | Exploit Technical Description Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2017-02-09 20:59
Updated : 2024-02-04 19:11
NVD link : CVE-2017-5602
Mitre link : CVE-2017-5602
CVE.ORG link : CVE-2017-5602
JSON object : View
Products Affected
jappix_project
- jappix