CVE-2016-9928

Severity CVSS v4.0:
Pending analysis
Type:
CWE-269 Improper Privilege Management
Publication date:
06/02/2020
Last modified:
01/01/2022

Description

MCabber before 1.0.4 is vulnerable to roster push attacks, which allows remote attackers to intercept communications, or add themselves as an entity on a 3rd party's roster as another user, which will also garner associated privileges, via crafted XMPP packets.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mcabber:mcabber:*:*:*:*:*:*:*:* 1.0.0 (including) 1.0.4 (excluding)
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*