An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks. This CVE is for yaxim and Bruno (0.8.6 - 0.8.8; Android).
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "0.8.6"
},
{
"introduced": "0"
},
{
"last_affected": "0.8.7"
},
{
"introduced": "0"
},
{
"last_affected": "0.8.8"
},
{
"introduced": "0"
},
{
"last_affected": "0.8.6"
},
{
"introduced": "0"
},
{
"last_affected": "0.8.7"
},
{
"introduced": "0"
},
{
"last_affected": "0.8.8"
}
]
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-5589.json"
"2026-04-11T03:11:42Z"
[
{
"target": {
"file": "src/org/yaxim/androidclient/service/SmackableImp.java",
"function": "processPacket"
},
"id": "CVE-2017-5589-2ee27eff",
"source": "https://github.com/ge0rg/yaxim/commit/65a38dc77545d9568732189e86089390f0ceaf9f",
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 3926.0,
"function_hash": "172370957006944829851377657957829823161"
},
"signature_version": "v1"
},
{
"target": {
"file": "src/org/yaxim/androidclient/service/SmackableImp.java"
},
"id": "CVE-2017-5589-b4dd117c",
"source": "https://github.com/ge0rg/yaxim/commit/65a38dc77545d9568732189e86089390f0ceaf9f",
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"153737100144617991198265298819933771344",
"14142142644532598557007988398869176820",
"191608210482791009829108665398745144520",
"149708554919926206651512033937721213057"
]
},
"signature_version": "v1"
},
{
"target": {
"file": "src/org/yaxim/androidclient/service/SmackableImp.java",
"function": "registerMessageListener"
},
"id": "CVE-2017-5589-b7ef297a",
"source": "https://github.com/ge0rg/yaxim/commit/65a38dc77545d9568732189e86089390f0ceaf9f",
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 4734.0,
"function_hash": "281192577220386992273384113389427695740"
},
"signature_version": "v1"
}
]