Oval Definition:oval:org.opensuse.security:def:20175589
Revision Date:2022-06-30Version:1
Title:CVE-2017-5589
Description:

An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks. This CVE is for yaxim and Bruno (0.8.6 - 0.8.8; Android).
Family:unixClass:vulnerability
Status:Reference(s):CVE-2017-5589
Mitre CVE-2017-5589
SUSE CVE-2017-5589
openSUSE-SU-2017:0515-1
Platform(s):openSUSE Leap 42.2
openSUSE Tumbleweed
Product(s):
Definition Synopsis
  • openSUSE Leap 42.2 is installed
  • AND Package Information
  • mcabber-1.0.5-6.1 is installed
  • AND mcabber is signed with openSUSE key
  • OR
  • mcabber-devel-1.0.5-6.1 is installed
  • AND mcabber-devel is signed with openSUSE key
  • Definition Synopsis
  • openSUSE Tumbleweed is installed
  • AND Package Information
  • python36-sleekxmpp-1.3.3-4.18 is installed
  • OR python36-slixmpp-1.5.2-1.9 is installed
  • OR python38-sleekxmpp-1.3.3-4.18 is installed
  • OR python38-slixmpp-1.5.2-1.9 is installed
  • OR python39-sleekxmpp-1.3.3-4.18 is installed
  • OR python39-slixmpp-1.5.2-1.9 is installed
  • BACK