PT-2017-16596 · Sleekxmpp+3 · Sleekxmpp+3

Published

2017-02-09

·

Updated

2022-05-13

·

CVE-2017-5591

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions SleekXMPP versions 1.3.1 and earlier Slixmpp versions 1.2.3 and earlier poezio versions 0.8 through 0.10
Description The issue is related to an incorrect implementation of XEP-0280: Message Carbons in multiple XMPP clients. This allows a remote attacker to impersonate any user in the vulnerable application's display, enabling various kinds of social engineering attacks.
Recommendations For SleekXMPP versions 1.3.1 and earlier, update to a version later than 1.3.1. For Slixmpp versions 1.2.3 and earlier, update to a version later than 1.2.3. For poezio versions 0.8 through 0.10, update to a version later than 0.10.

Exploit

Fix

RCE

Origin Validation Error

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-1284
CVE-2017-5591
GHSA-C35G-JR5F-H83P
PYSEC-2017-103
PYSEC-2017-104

Affected Products

Alt Linux
Sleekxmpp
Slixmpp
Poezio