An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks. This CVE is for ChatSecure (3.2.0 - 4.0.0; only iOS) and Zom (all versions up to 1.0.11; only iOS).
[
{
"signature_type": "Line",
"target": {
"file": "ChatSecure/Classes/Controllers/XMPP/OTRXMPPMessageYapStroage.h"
},
"deprecated": false,
"source": "https://github.com/chatsecure/chatsecure-ios/commit/a340b4bb519227d89f85f2716a10a197a65d4856",
"id": "CVE-2017-5590-938e6ade",
"digest": {
"threshold": 0.9,
"line_hashes": [
"209646930666600076338162883704913539223",
"273743801690347581989655561691106847040",
"180914673249055266491887896319264413105",
"131330495340382908432222828795181426082"
]
},
"signature_version": "v1"
}
]