PT-2017-16596 · Sleekxmpp+3 · Sleekxmpp+3

Publicado

2017-02-09

·

Atualizado

2022-05-13

·

CVE-2017-5591

CVSS v3.1

5.9

Média

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions SleekXMPP versions 1.3.1 and earlier Slixmpp versions 1.2.3 and earlier poezio versions 0.8 through 0.10
Description The issue is related to an incorrect implementation of XEP-0280: Message Carbons in multiple XMPP clients. This allows a remote attacker to impersonate any user in the vulnerable application's display, enabling various kinds of social engineering attacks.
Recommendations For SleekXMPP versions 1.3.1 and earlier, update to a version later than 1.3.1. For Slixmpp versions 1.2.3 and earlier, update to a version later than 1.2.3. For poezio versions 0.8 through 0.10, update to a version later than 0.10.

Exploit

Correção

RCE

Origin Validation Error

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2017-1284
CVE-2017-5591
GHSA-C35G-JR5F-H83P
PYSEC-2017-103
PYSEC-2017-104

Produtos afetados

Alt Linux
Sleekxmpp
Slixmpp
Poezio