PT-2017-16594 · Sleekxmpp+5 · Sleekxmpp+6

Georg Lukas

·

Publicado

2017-02-09

·

Atualizado

2025-04-22

·

CVE-2017-5589

CVSS v3.1

5.9

Média

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions yaxim and Bruno versions 0.8.6 through 0.8.8 SleekXMPP versions up to 1.3.1 Slixmpp versions up to 1.2.3 poezio versions 0.8 through 0.10 Movim versions 0.8 through 0.10 converse.js versions prior to 1.0.7 for 1.x or 2.0.5 for 2.x
Description An incorrect implementation of XEP-0280: Message Carbons in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks.
Recommendations For yaxim and Bruno versions 0.8.6 through 0.8.8, upgrade to a version outside of this range. For SleekXMPP versions up to 1.3.1, upgrade to version 1.3.2 or later. For Slixmpp versions up to 1.2.3, upgrade to version 1.2.4 or later. For poezio versions 0.8 through 0.10, upgrade to version 0.11 or later. For Movim versions 0.8 through 0.10, upgrade to version 0.11 or later. For converse.js 1.x, upgrade to 1.0.7 or later. For converse.js 2.x, upgrade to 2.0.5 or later.

Exploit

Correção

Origin Validation Error

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2017-1284
ALT-PU-2017-1350
CVE-2017-5589
GHSA-C35G-JR5F-H83P
GHSA-HQ38-V658-G3WP
GHSA-W973-2QCC-P78X
OPENSUSE-SU-2024:11273-1
OPENSUSE-SU-2024:11274-1
OPENSUSE-SU-2024:14165-1
OPENSUSE-SU-2025:15016-1
PYSEC-2017-103
PYSEC-2017-104

Produtos afetados

Bruno
Movim
Sleekxmpp
Slixmpp
Converse.Js
Poezio
Yaxim