PT-2017-16596 · Sleekxmpp+3 · Sleekxmpp+3
Publicado
2017-02-09
·
Atualizado
2022-05-13
·
CVE-2017-5591
CVSS v3.1
5.9
Média
| Vetor | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
SleekXMPP versions 1.3.1 and earlier
Slixmpp versions 1.2.3 and earlier
poezio versions 0.8 through 0.10
Description
The issue is related to an incorrect implementation of XEP-0280: Message Carbons in multiple XMPP clients. This allows a remote attacker to impersonate any user in the vulnerable application's display, enabling various kinds of social engineering attacks.
Recommendations
For SleekXMPP versions 1.3.1 and earlier, update to a version later than 1.3.1.
For Slixmpp versions 1.2.3 and earlier, update to a version later than 1.2.3.
For poezio versions 0.8 through 0.10, update to a version later than 0.10.
Exploit
Correção
RCE
Origin Validation Error
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Sleekxmpp
Slixmpp
Poezio