MCabber before 1.0.4 is vulnerable to roster push attacks, which allows remote attackers to intercept communications, or add themselves as an entity on a 3rd partys roster as another user, which will also garner associated privileges, via crafted XMPP packets.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mcabber | Mcabber | 1.0.0 (including) | 1.0.4 (excluding) |
Mcabber | Ubuntu | artful | * |
Mcabber | Ubuntu | precise | * |
Mcabber | Ubuntu | trusty | * |
Mcabber | Ubuntu | xenial | * |
Mcabber | Ubuntu | yakkety | * |
Mcabber | Ubuntu | zesty | * |