PT-2017-16596 · Sleekxmpp+3 · Sleekxmpp+3
Published
2017-02-09
·
Updated
2022-05-13
·
CVE-2017-5591
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
SleekXMPP versions 1.3.1 and earlier
Slixmpp versions 1.2.3 and earlier
poezio versions 0.8 through 0.10
Description
The issue is related to an incorrect implementation of XEP-0280: Message Carbons in multiple XMPP clients. This allows a remote attacker to impersonate any user in the vulnerable application's display, enabling various kinds of social engineering attacks.
Recommendations
For SleekXMPP versions 1.3.1 and earlier, update to a version later than 1.3.1.
For Slixmpp versions 1.2.3 and earlier, update to a version later than 1.2.3.
For poezio versions 0.8 through 0.10, update to a version later than 0.10.
Exploit
Fix
RCE
Origin Validation Error
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Sleekxmpp
Slixmpp
Poezio