PT-2017-16595 · Chatsecure+1 · Chatsecure+1
Georg Lukas
·
Publicado
2017-02-09
·
Atualizado
2017-03-01
·
CVE-2017-5590
CVSS v3.1
5.9
Média
| Vetor | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
ChatSecure versions 3.2.0 through 4.0.0
Zom versions prior to 1.0.11
Description
The issue is related to an incorrect implementation of XEP-0280: Message Carbons in multiple XMPP clients. This allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display, enabling various kinds of social engineering attacks.
Recommendations
For ChatSecure versions 3.2.0 through 4.0.0, update to a version outside of this range to resolve the issue.
For Zom versions prior to 1.0.11, update to version 1.0.11 or later to fix the problem.
Exploit
Correção
Origin Validation Error
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Chatsecure
Zom