{"id":"CVE-2017-5589","details":"An incorrect implementation of \"XEP-0280: Message Carbons\" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks. This CVE is for yaxim and Bruno (0.8.6 - 0.8.8; Android).","modified":"2026-07-15T18:29:26.575595513Z","published":"2017-02-09T20:59:00.153Z","related":["openSUSE-SU-2024:11273-1","openSUSE-SU-2024:11274-1","openSUSE-SU-2024:14165-1","openSUSE-SU-2025:15016-1","openSUSE-SU-2026:11272-1"],"references":[{"type":"WEB","url":"http://www.securityfocus.com/bid/96170"},{"type":"FIX","url":"https://github.com/ge0rg/yaxim/commit/65a38dc77545d9568732189e86089390f0ceaf9f"},{"type":"EVIDENCE","url":"http://openwall.com/lists/oss-security/2017/02/09/29"},{"type":"EVIDENCE","url":"https://rt-solutions.de/en/2017/02/CVE-2017-5589_xmpp_carbons/"},{"type":"EVIDENCE","url":"https://rt-solutions.de/wp-content/uploads/2017/02/CVE-2017-5589_xmpp_carbons.pdf"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/ge0rg/yaxim","events":[{"introduced":"0"},{"last_affected":"be5abb31041c3da8bd96f3c60af254bb0a6029d5"},{"last_affected":"cae23966f8516d76e2ee6f98711a2c7d4480f72f"},{"last_affected":"7e91fd11dc7f831e50ce4511fb9419c5b48ee8c1"}],"database_specific":{"cpe":["cpe:2.3:a:yaxim:bruno:0.8.6:*:*:*:*:android:*:*","cpe:2.3:a:yaxim:bruno:0.8.7:*:*:*:*:android:*:*","cpe:2.3:a:yaxim:bruno:0.8.8:*:*:*:*:android:*:*","cpe:2.3:a:yaxim:yaxim:0.8.6:*:*:*:*:android:*:*","cpe:2.3:a:yaxim:yaxim:0.8.7:*:*:*:*:android:*:*","cpe:2.3:a:yaxim:yaxim:0.8.8:*:*:*:*:android:*:*"],"extracted_events":[{"introduced":"0"},{"last_affected":"0.8.6"},{"last_affected":"0.8.7"},{"last_affected":"0.8.8"}],"source":"CPE_FIELD"}}],"versions":["0.8.8-bruno","0.8.7b-bruno","0.8.7","0.8.6b","0.8.6b-bruno","0.8.6","0.8.5","0.8.4","0.8.3","0.8.2","0.8.1","0.8.0","0.7.7","0.7.6","0.7.5","0.7.3","0.7.2","0.7.1"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-5589.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}