CVE-2017-5606
Summary
| CVE | CVE-2017-5606 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-02-09 20:59:00 UTC |
| Updated | 2020-01-22 16:01:00 UTC |
| Description | An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks. This CVE is for Xabber (only if manually enabled: 1.0.30, 1.0.30 VIP, beta 1.0.3 - 1.0.74; Android). |
Risk And Classification
Problem Types: CWE-20 | CWE-346
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2017-5589+ Multiple XMPP Clients User Impersonation Vulnerability – rt-solutions.de – experts you can trust | MISC | rt-solutions.de | Exploit, Technical Description, Third Party Advisory |
| Xabber XMPP Client CVE-2017-5606 User Impersonation Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| rt-solutions.de/wp-content/uploads/2017/02/CVE-2017-5589_xmpp_carbons.pdf | MISC | rt-solutions.de | Exploit, Technical Description, Third Party Advisory |
| oss-security - CVE-2017-5589+ Multiple XMPP Clients User Impersonation Vulnerability | MISC | openwall.com | Exploit, Mailing List, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.