PT-2017-16594 · Sleekxmpp+5 · Sleekxmpp+6

Georg Lukas

·

Published

2017-02-09

·

Updated

2025-04-22

·

CVE-2017-5589

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions yaxim and Bruno versions 0.8.6 through 0.8.8 SleekXMPP versions up to 1.3.1 Slixmpp versions up to 1.2.3 poezio versions 0.8 through 0.10 Movim versions 0.8 through 0.10 converse.js versions prior to 1.0.7 for 1.x or 2.0.5 for 2.x
Description An incorrect implementation of XEP-0280: Message Carbons in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks.
Recommendations For yaxim and Bruno versions 0.8.6 through 0.8.8, upgrade to a version outside of this range. For SleekXMPP versions up to 1.3.1, upgrade to version 1.3.2 or later. For Slixmpp versions up to 1.2.3, upgrade to version 1.2.4 or later. For poezio versions 0.8 through 0.10, upgrade to version 0.11 or later. For Movim versions 0.8 through 0.10, upgrade to version 0.11 or later. For converse.js 1.x, upgrade to 1.0.7 or later. For converse.js 2.x, upgrade to 2.0.5 or later.

Exploit

Fix

Origin Validation Error

RCE

Weakness Enumeration

Related Identifiers

ALT-PU-2017-1284
ALT-PU-2017-1350
CVE-2017-5589
GHSA-C35G-JR5F-H83P
GHSA-HQ38-V658-G3WP
GHSA-W973-2QCC-P78X
OPENSUSE-SU-2024:11273-1
OPENSUSE-SU-2024:11274-1
OPENSUSE-SU-2024:14165-1
OPENSUSE-SU-2025:15016-1
PYSEC-2017-103
PYSEC-2017-104

Affected Products

Bruno
Movim
Sleekxmpp
Slixmpp
Converse.Js
Poezio
Yaxim