MidnightBSD

Advisories for jappix_project

CVE-2017-5602 MEDIUM

An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks. This CVE is for jappix 1.0.0 to 1.1.6.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,CWE-346,

Products Affected

Vendor Product Version
jappix_project jappix 1.0.0
jappix_project jappix 1.1.2
jappix_project jappix 1.0.6
jappix_project jappix 1.1.6
jappix_project jappix 1.1.1
jappix_project jappix 1.0.4
jappix_project jappix 1.0.1
jappix_project jappix 1.0.7
jappix_project jappix 1.0.5
jappix_project jappix 1.0.3
jappix_project jappix 1.1.3
jappix_project jappix 1.1.5
jappix_project jappix 1.0.2
jappix_project jappix 1.1.0
jappix_project jappix 1.1.4