Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2017-5591

Опубликовано: 09 фев. 2017
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.3
CVSS3: 5.9

Описание

An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks. This CVE is for SleekXMPP up to 1.3.1 and Slixmpp all versions up to 1.2.3, as bundled in poezio (0.8 - 0.10) and other products.

РелизСтатусПримечание
artful

ignored

end of life
bionic

not-affected

1.3.3-3
cosmic

not-affected

1.3.3-3
devel

DNE

disco

not-affected

1.3.3-3
eoan

not-affected

1.3.3-3
esm-apps/bionic

not-affected

1.3.3-3
esm-apps/focal

not-affected

1.3.3-3
esm-apps/jammy

not-affected

1.3.3-3
esm-apps/xenial

needed

Показывать по

РелизСтатусПримечание
artful

ignored

end of life
bionic

not-affected

1.2.2-1.1build2
cosmic

not-affected

1.2.2-1.1build2
devel

not-affected

1.2.2-1.1build2
disco

not-affected

1.2.2-1.1build2
eoan

not-affected

1.2.2-1.1build2
esm-apps/bionic

not-affected

1.2.2-1.1build2
esm-apps/focal

not-affected

1.2.2-1.1build2
esm-apps/jammy

not-affected

1.2.2-1.1build2
esm-apps/noble

not-affected

1.2.2-1.1build2

Показывать по

EPSS

Процентиль: 63%
0.00456
Низкий

4.3 Medium

CVSS2

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
nvd
почти 9 лет назад

An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks. This CVE is for SleekXMPP up to 1.3.1 and Slixmpp all versions up to 1.2.3, as bundled in poezio (0.8 - 0.10) and other products.

CVSS3: 5.9
debian
почти 9 лет назад

An incorrect implementation of "XEP-0280: Message Carbons" in multiple ...

CVSS3: 5.9
github
больше 3 лет назад

SleekXMPP and Slixmpp Incorrect Implementation of Message Carbons

EPSS

Процентиль: 63%
0.00456
Низкий

4.3 Medium

CVSS2

5.9 Medium

CVSS3