{"id":"CVE-2017-5602","details":"An incorrect implementation of \"XEP-0280: Message Carbons\" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks. This CVE is for jappix 1.0.0 to 1.1.6.","modified":"2026-03-15T22:16:25.636115Z","published":"2017-02-09T20:59:00.373Z","references":[{"type":"WEB","url":"http://www.securityfocus.com/bid/96176"},{"type":"FIX","url":"https://github.com/jappix/jappix/commit/ea6de7c65b80880bdf85df47c1a8a5d3d68491af"},{"type":"EVIDENCE","url":"http://openwall.com/lists/oss-security/2017/02/09/29"},{"type":"EVIDENCE","url":"https://rt-solutions.de/en/2017/02/CVE-2017-5589_xmpp_carbons/"},{"type":"EVIDENCE","url":"https://rt-solutions.de/wp-content/uploads/2017/02/CVE-2017-5589_xmpp_carbons.pdf"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/jappix/jappix","events":[{"introduced":"0"},{"last_affected":"67da6a9301b2ca016aaa2f81c110e80cea77e3e6"},{"introduced":"0"},{"last_affected":"9a5c5e4f4abc567f9e0a31f970c15356780a4c29"},{"introduced":"0"},{"last_affected":"f8fed985bda2457b19f9efbed72f9960174262c6"},{"introduced":"0"},{"last_affected":"8f3c32c4f60379f881199ba762a67603320094ef"},{"introduced":"0"},{"last_affected":"16f05ab89f3144d5db54ea5b8e64c219827454bc"},{"introduced":"0"},{"last_affected":"1d82c80efb9f42437d726327ff52885fe8a0c845"},{"introduced":"0"},{"last_affected":"8c40527f30f660823cd05b7fed7e06759fae5c66"},{"introduced":"0"},{"last_affected":"894e7a827c179ff575f847ebfdfc98f56c089cb9"},{"introduced":"0"},{"last_affected":"dee0efa21aaa32c2af88054d5f42c901013bd880"},{"introduced":"0"},{"last_affected":"54437753025f62554840f7974ae2019a7dbf5cb0"},{"introduced":"0"},{"last_affected":"b1e50c586b8d6096cbee9c1b7dab0cbec7a7f6a0"},{"introduced":"0"},{"last_affected":"f1267bfa0811adbf43ffdcd1a1f76ecda8d61c3f"},{"introduced":"0"},{"last_affected":"1d4bc4b5fe304cbb96cf36d4004cbb1aa192f077"},{"introduced":"0"},{"last_affected":"8569462a96ead9d31679593d726615bfc1443355"},{"introduced":"0"},{"last_affected":"97e3d81c3941fccd310c8f5fc2a55deb7f68bb39"},{"fixed":"ea6de7c65b80880bdf85df47c1a8a5d3d68491af"}],"database_specific":{"versions":[{"introduced":"0"},{"last_affected":"1.0.0"},{"introduced":"0"},{"last_affected":"1.0.1"},{"introduced":"0"},{"last_affected":"1.0.2"},{"introduced":"0"},{"last_affected":"1.0.3"},{"introduced":"0"},{"last_affected":"1.0.4"},{"introduced":"0"},{"last_affected":"1.0.5"},{"introduced":"0"},{"last_affected":"1.0.6"},{"introduced":"0"},{"last_affected":"1.0.7"},{"introduced":"0"},{"last_affected":"1.1.0"},{"introduced":"0"},{"last_affected":"1.1.1"},{"introduced":"0"},{"last_affected":"1.1.2"},{"introduced":"0"},{"last_affected":"1.1.3"},{"introduced":"0"},{"last_affected":"1.1.4"},{"introduced":"0"},{"last_affected":"1.1.5"},{"introduced":"0"},{"last_affected":"1.1.6"}]}}],"versions":["0.9","0.9.1","0.9.2","0.9.3","0.9.4","0.9.5","0.9.6","0.9.7","0.9.8","0.9.9","1.0.0","1.0.1","1.0.2","1.0.3","1.0.4","1.0.5","1.0.6","1.0.7","1.1.0","1.1.1","1.1.2","1.1.3","1.1.4","1.1.5","1.1.6"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-5602.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}