VYPR
Medium severity5.9NVD Advisory· Published Feb 9, 2017· Updated May 13, 2026

CVE-2017-5589

CVE-2017-5589

Description

An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks. This CVE is for yaxim and Bruno (0.8.6 - 0.8.8; Android).

Affected products

6
  • Yaxim/Bruno3 versions
    cpe:2.3:a:yaxim:bruno:0.8.6:*:*:*:*:android:*:*+ 2 more
    • cpe:2.3:a:yaxim:bruno:0.8.6:*:*:*:*:android:*:*
    • cpe:2.3:a:yaxim:bruno:0.8.7:*:*:*:*:android:*:*
    • cpe:2.3:a:yaxim:bruno:0.8.8:*:*:*:*:android:*:*
  • Yaxim/Yaxim3 versions
    cpe:2.3:a:yaxim:yaxim:0.8.6:*:*:*:*:android:*:*+ 2 more
    • cpe:2.3:a:yaxim:yaxim:0.8.6:*:*:*:*:android:*:*
    • cpe:2.3:a:yaxim:yaxim:0.8.7:*:*:*:*:android:*:*
    • cpe:2.3:a:yaxim:yaxim:0.8.8:*:*:*:*:android:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.