{"id":"CVE-2017-5589","details":"An incorrect implementation of \"XEP-0280: Message Carbons\" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks. This CVE is for yaxim and Bruno (0.8.6 - 0.8.8; Android).","modified":"2026-07-15T10:14:36.132906724Z","published":"2017-02-09T20:59:00.153Z","related":["openSUSE-SU-2024:11273-1","openSUSE-SU-2024:11274-1","openSUSE-SU-2024:14165-1","openSUSE-SU-2025:15016-1","openSUSE-SU-2026:11272-1"],"references":[{"type":"WEB","url":"http://www.securityfocus.com/bid/96170"},{"type":"FIX","url":"https://github.com/ge0rg/yaxim/commit/65a38dc77545d9568732189e86089390f0ceaf9f"},{"type":"EVIDENCE","url":"http://openwall.com/lists/oss-security/2017/02/09/29"},{"type":"EVIDENCE","url":"https://rt-solutions.de/en/2017/02/CVE-2017-5589_xmpp_carbons/"},{"type":"EVIDENCE","url":"https://rt-solutions.de/wp-content/uploads/2017/02/CVE-2017-5589_xmpp_carbons.pdf"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/ge0rg/yaxim","events":[{"introduced":"be5abb31041c3da8bd96f3c60af254bb0a6029d5"},{"last_affected":"7e91fd11dc7f831e50ce4511fb9419c5b48ee8c1"},{"fixed":"65a38dc77545d9568732189e86089390f0ceaf9f"}],"database_specific":{"cpe":["cpe:2.3:a:yaxim:bruno:0.8.6:*:*:*:*:android:*:*","cpe:2.3:a:yaxim:yaxim:0.8.6:*:*:*:*:android:*:*","cpe:2.3:a:yaxim:bruno:0.8.7:*:*:*:*:android:*:*","cpe:2.3:a:yaxim:yaxim:0.8.7:*:*:*:*:android:*:*","cpe:2.3:a:yaxim:bruno:0.8.8:*:*:*:*:android:*:*","cpe:2.3:a:yaxim:yaxim:0.8.8:*:*:*:*:android:*:*"],"extracted_events":[{"introduced":"0.8.6"},{"last_affected":"0.8.6"},{"introduced":"0.8.7"},{"last_affected":"0.8.7"},{"introduced":"0.8.8"},{"last_affected":"0.8.8"}],"source":["CPE_STRING","REFERENCES"]}}],"versions":["0.8.6","0.8.7","0.8.8"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-5589.json","vanir_signatures_modified":"2026-07-08T10:55:28Z","vanir_signatures":[{"source":"https://github.com/ge0rg/yaxim/commit/65a38dc77545d9568732189e86089390f0ceaf9f","target":{"function":"processPacket","file":"src/org/yaxim/androidclient/service/SmackableImp.java"},"deprecated":false,"digest":{"function_hash":"172370957006944829851377657957829823161","length":3926},"id":"CVE-2017-5589-2ee27eff","signature_type":"Function","signature_version":"v1"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/ge0rg/yaxim/commit/65a38dc77545d9568732189e86089390f0ceaf9f","target":{"file":"src/org/yaxim/androidclient/service/SmackableImp.java"},"deprecated":false,"digest":{"line_hashes":["153737100144617991198265298819933771344","14142142644532598557007988398869176820","191608210482791009829108665398745144520","149708554919926206651512033937721213057"],"threshold":0.9},"id":"CVE-2017-5589-b4dd117c"},{"signature_version":"v1","source":"https://github.com/ge0rg/yaxim/commit/65a38dc77545d9568732189e86089390f0ceaf9f","target":{"file":"src/org/yaxim/androidclient/service/SmackableImp.java","function":"registerMessageListener"},"deprecated":false,"digest":{"function_hash":"281192577220386992273384113389427695740","length":4734},"id":"CVE-2017-5589-b7ef297a","signature_type":"Function"}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}