PT-2019-11261 · Aioxmpp · Aioxmpp

Horazont

·

Publicado

2019-02-04

·

Atualizado

2021-07-21

·

CVE-2019-1000007

CVSS v4.0

8.3

Alta

VetorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: aioxmpp versions 0.10.2 and earlier
Description: The issue is related to improper handling of structural elements in the Stanza Parser, specifically during error processing in the aioxmpp.xso.model.guard function. This can result in Denial of Service or potentially allow data injection in a different context. A crafted stanza sent to an application using the vulnerable components can cause the application to reconnect, potentially leading to data loss. The vulnerability appears to be exploitable remotely.
Recommendations: For versions 0.10.2 and earlier, update to version 0.10.3 or later to resolve the issue. As a temporary workaround, consider not using xso error handlers or avoiding the use of the error suppression function to mitigate the vulnerability.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-1000007
GHSA-32F7-CMR3-VPJV
GHSA-6M9G-JR8C-CQW3
PYSEC-2019-1

Produtos afetados

Aioxmpp