Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-0364

Опубликовано: 31 янв. 2014
Источник: redhat
CVSS2: 4.3

Описание

The ParseRoster component in the Ignite Realtime Smack XMPP API before 4.0.0-rc1 does not verify the from attribute of a roster-query IQ stanza, which allows remote attackers to spoof IQ responses via a crafted attribute.

It was found that the ParseRoster component in the Smack XMPP API did not verify the From attribute of a roster-query IQ stanza. A remote attacker could use this flaw to spoof IQ responses.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss BRMS 5smackWill not fix
Red Hat JBoss Enterprise Web Server 1anythingUnder investigation
Red Hat JBoss Enterprise Web Server 1fuse-6Affected
Red Hat JBoss Enterprise Web Server 1fuse-esb-7Will not fix
Red Hat JBoss BPMS 6.0smackFixedRHSA-2014:081930.06.2014
Red Hat JBoss BRMS 6.0smackFixedRHSA-2014:081830.06.2014
Red Hat JBoss Fuse 6.2FixedRHSA-2015:117623.06.2015

Показывать по

Дополнительная информация

Статус:

Moderate

4.3 Medium

CVSS2

Связанные уязвимости

nvd
почти 12 лет назад

The ParseRoster component in the Ignite Realtime Smack XMPP API before 4.0.0-rc1 does not verify the from attribute of a roster-query IQ stanza, which allows remote attackers to spoof IQ responses via a crafted attribute.

github
больше 3 лет назад

The ParseRoster component in the Ignite Realtime Smack XMPP API before 4.0.0-rc1 does not verify the from attribute of a roster-query IQ stanza, which allows remote attackers to spoof IQ responses via a crafted attribute.

4.3 Medium

CVSS2