Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-9928

Опубликовано: 06 фев. 2020
Источник: debian

Описание

MCabber before 1.0.4 is vulnerable to roster push attacks, which allows remote attackers to intercept communications, or add themselves as an entity on a 3rd party's roster as another user, which will also garner associated privileges, via crafted XMPP packets.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
mcabberfixed0.10.2-1.1package

Примечания

  • https://bitbucket.org/McKael/mcabber-crew/commits/6e1ead98930d7dd0a520ad17c720ae4908429033/raw

  • Similar issue for mcabber as for gajim in CVE-2015-8688

  • https://www.openwall.com/lists/oss-security/2016/12/09/5

Связанные уязвимости

CVSS3: 7.4
ubuntu
около 6 лет назад

MCabber before 1.0.4 is vulnerable to roster push attacks, which allows remote attackers to intercept communications, or add themselves as an entity on a 3rd party's roster as another user, which will also garner associated privileges, via crafted XMPP packets.

CVSS3: 7.4
nvd
около 6 лет назад

MCabber before 1.0.4 is vulnerable to roster push attacks, which allows remote attackers to intercept communications, or add themselves as an entity on a 3rd party's roster as another user, which will also garner associated privileges, via crafted XMPP packets.

github
больше 3 лет назад

MCabber before 1.0.4 is vulnerable to roster push attacks, which allows remote attackers to intercept communications, or add themselves as an entity on a 3rd party's roster as another user, which will also garner associated privileges, via crafted XMPP packets.

suse-cvrf
около 9 лет назад

Security update for python3-sleekxmpp