CVE-2017-5591
Summary
| CVE | CVE-2017-5591 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-02-09 20:59:00 UTC |
| Updated | 2020-01-22 14:13:00 UTC |
| Description | An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks. This CVE is for SleekXMPP up to 1.3.1 and Slixmpp all versions up to 1.2.3, as bundled in poezio (0.8 - 0.10) and other products. |
Risk And Classification
Problem Types: CWE-20 | CWE-346
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Poezio | Poezio | 0.10 | All | All | All |
| Application | Poezio | Poezio | 0.8 | All | All | All |
| Application | Poezio | Poezio | 0.8.1 | All | All | All |
| Application | Poezio | Poezio | 0.9 | All | All | All |
| Application | Poezio | Poezio | 0.10 | All | All | All |
| Application | Poezio | Poezio | 0.8 | All | All | All |
| Application | Poezio | Poezio | 0.8.1 | All | All | All |
| Application | Poezio | Poezio | 0.9 | All | All | All |
| Application | Sleekxmpp Project | Sleekxmpp | All | All | All | All |
| Application | Slixmpp Project | Slixmpp | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2017-5589+ Multiple XMPP Clients User Impersonation Vulnerability – rt-solutions.de – experts you can trust | MISC | rt-solutions.de | Exploit, Technical Description, Third Party Advisory |
| Poezio/SleekXMPP/Slixmpp CVE-2017-5591 User Impersonation Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| rt-solutions.de/wp-content/uploads/2017/02/CVE-2017-5589_xmpp_carbons.pdf | MISC | rt-solutions.de | Exploit, Technical Description, Third Party Advisory |
| oss-security - CVE-2017-5589+ Multiple XMPP Clients User Impersonation Vulnerability | MISC | openwall.com | Exploit, Mailing List, Third Party Advisory |
| Fix carbons · poezio/slixmpp@22664ee · GitHub | MISC | github.com | Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.