MCabber before 1.0.4 is vulnerable to roster push attacks, which allows remote attackers to intercept communications, or add themselves as an entity on a 3rd party's roster as another user, which will also garner associated privileges, via crafted XMPP packets.

Project Subscriptions

Vendors Products
Canonical Subscribe
Ubuntu Linux Subscribe
Debian Linux Subscribe
Mcabber Subscribe
Mcabber Subscribe
Advisories
Source ID Title
Debian DLA Debian DLA DLA-2260-1 mcabber security update
EUVD EUVD EUVD-2016-10715 MCabber before 1.0.4 is vulnerable to roster push attacks, which allows remote attackers to intercept communications, or add themselves as an entity on a 3rd party's roster as another user, which will also garner associated privileges, via crafted XMPP packets.
Ubuntu USN Ubuntu USN USN-4506-1 MCabber vulnerability
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: debian

Published:

Updated: 2024-08-06T03:07:31.382Z

Reserved: 2016-12-11T00:00:00

Link: CVE-2016-9928

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-02-06T14:15:10.957

Modified: 2024-11-21T03:02:01.670

Link: CVE-2016-9928

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses