PT-2019-11261 · Aioxmpp · Aioxmpp

Horazont

·

Published

2019-02-04

·

Updated

2021-07-21

·

CVE-2019-1000007

CVSS v4.0

8.3

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: aioxmpp versions 0.10.2 and earlier
Description: The issue is related to improper handling of structural elements in the Stanza Parser, specifically during error processing in the aioxmpp.xso.model.guard function. This can result in Denial of Service or potentially allow data injection in a different context. A crafted stanza sent to an application using the vulnerable components can cause the application to reconnect, potentially leading to data loss. The vulnerability appears to be exploitable remotely.
Recommendations: For versions 0.10.2 and earlier, update to version 0.10.3 or later to resolve the issue. As a temporary workaround, consider not using xso error handlers or avoiding the use of the error suppression function to mitigate the vulnerability.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-1000007
GHSA-32F7-CMR3-VPJV
GHSA-6M9G-JR8C-CQW3
PYSEC-2019-1

Affected Products

Aioxmpp