VYPR

rpm package

opensuse/libqxmpp&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/libqxmpp&distro=openSUSE%20Tumbleweed

Vulnerabilities (2)

  • CVE-2016-9928HigFeb 6, 2020
    affected < 1.16.1-1.1fixed 1.16.1-1.1

    MCabber before 1.0.4 is vulnerable to roster push attacks, which allows remote attackers to intercept communications, or add themselves as an entity on a 3rd party's roster as another user, which will also garner associated privileges, via crafted XMPP packets.

  • CVE-2017-5603MedFeb 9, 2017
    affected < 1.16.1-1.1fixed 1.16.1-1.1

    An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks. This CVE is for Jitsi 2.