SB2017020931 - Spoofing attack in Movim
Published: February 9, 2017 Updated: October 4, 2023
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Spoofing attack (CVE-ID: CVE-2017-5605)
The vulnerability allows a remote attacker to impersonate any application's user.
The vulnerability exists due to incorrect implementation of "XEP-0280: Message Carbons". A remote attacker can impersonate any user, including contacts, in the vulnerable application.
Remediation
Install update from vendor's website.
References
- http://openwall.com/lists/oss-security/2017/02/09/29
- http://www.securityfocus.com/bid/96177
- https://rt-solutions.de/en/2017/02/CVE-2017-5589_xmpp_carbons/
- https://rt-solutions.de/wp-content/uploads/2017/02/CVE-2017-5589_xmpp_carbons.pdf
- https://github.com/movim/movim/commit/838b0a42efc3b67cc17d63e25ae1d0ea849cd89b