Advisory Database
  • Advisories
  • Dependency Scanning
  1. pypi
  2. ›
  3. slixmpp
  4. ›
  5. CVE-2017-5591

CVE-2017-5591: SleekXMPP and Slixmpp Incorrect Implementation of Message Carbons

May 13, 2022 (updated October 22, 2024)

An incorrect implementation of “XEP-0280: Message Carbons” in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application’s display. This allows for various kinds of social engineering attacks. This CVE is for SleekXMPP up to 1.3.1 and Slixmpp all versions up to 1.2.3, as bundled in poezio (0.8 - 0.10) and other products.

References

  • github.com/advisories/GHSA-c35g-jr5f-h83p
  • github.com/fritzy/SleekXMPP/commit/285495d5ee2427d93d961ceedcd1829383e5196d
  • github.com/fritzy/SleekXMPP/issues/442
  • github.com/poezio/slixmpp
  • github.com/poezio/slixmpp/commit/22664ee7b86c8e010f312b66d12590fb47160ad8
  • github.com/pypa/advisory-database/tree/main/vulns/sleekxmpp/PYSEC-2017-103.yaml
  • github.com/pypa/advisory-database/tree/main/vulns/slixmpp/PYSEC-2017-104.yaml
  • nvd.nist.gov/vuln/detail/CVE-2017-5591
  • pypi.org/project/sleekxmpp
  • pypi.org/project/slixmpp
  • rt-solutions.de/en/2017/02/CVE-2017-5589_xmpp_carbons
  • rt-solutions.de/wp-content/uploads/2017/02/CVE-2017-5589_xmpp_carbons.pdf
  • web.archive.org/web/20200227192025/http://www.securityfocus.com/bid/96166

Code Behaviors & Features

Detect and mitigate CVE-2017-5591 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 1.2.4

Fixed versions

  • 1.2.4

Solution

Upgrade to version 1.2.4 or above.

Impact 5.9 MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

Learn more about CVSS

Weakness

  • CWE-940: Improper Verification of Source of a Communication Channel

Source file

pypi/slixmpp/CVE-2017-5591.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:16:10 +0000.