An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks. This CVE is for yaxim and Bruno (0.8.6 - 0.8.8; Android).
[
{
"digest": {
"function_hash": "172370957006944829851377657957829823161",
"length": 3926.0
},
"target": {
"file": "src/org/yaxim/androidclient/service/SmackableImp.java",
"function": "processPacket"
},
"deprecated": false,
"source": "https://github.com/ge0rg/yaxim/commit/65a38dc77545d9568732189e86089390f0ceaf9f",
"id": "CVE-2017-5589-2ee27eff",
"signature_type": "Function",
"signature_version": "v1"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"153737100144617991198265298819933771344",
"14142142644532598557007988398869176820",
"191608210482791009829108665398745144520",
"149708554919926206651512033937721213057"
]
},
"target": {
"file": "src/org/yaxim/androidclient/service/SmackableImp.java"
},
"deprecated": false,
"source": "https://github.com/ge0rg/yaxim/commit/65a38dc77545d9568732189e86089390f0ceaf9f",
"id": "CVE-2017-5589-b4dd117c",
"signature_type": "Line",
"signature_version": "v1"
},
{
"digest": {
"function_hash": "281192577220386992273384113389427695740",
"length": 4734.0
},
"target": {
"file": "src/org/yaxim/androidclient/service/SmackableImp.java",
"function": "registerMessageListener"
},
"deprecated": false,
"source": "https://github.com/ge0rg/yaxim/commit/65a38dc77545d9568732189e86089390f0ceaf9f",
"id": "CVE-2017-5589-b7ef297a",
"signature_type": "Function",
"signature_version": "v1"
}
]