CVE-2014-0364: Medium severity igniterealtime Smack vulnerability
Common Vulnerabilities and Exposures assigned an identifier CVE-2014-0364 to the following vulnerability:
Name: CVE-2014-0364 URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0364 Assigned: 20131205 Reference: http://community.igniterealtime.org/blogs/ignite/2014/04/17/asmack-400-rc1-has-been-released Reference: CERT-VN:VU#489228 Reference: http://www.kb.cert.org/vuls/id/489228
The ParseRoster component in the Ignite Realtime Smack XMPP API before 4.0.0-rc1 does not verify the from attribute of a roster-query IQ stanza, which allows remote attackers to spoof IQ responses via a crafted attribute.
It is not clear whether this flaw affects the version of smack in Fedora. Both of these look to be needed to complete the fix:
http://issues.igniterealtime.org/browse/SMACK-533 http://issues.igniterealtime.org/browse/SMACK-538
Other sources
It was found that the ParseRoster component in the Smack XMPP API did not verify the From attribute of a roster-query IQ stanza. A remote attacker could use this flaw to spoof IQ responses.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ignite Realtime Smack XMPP APIto a version that resolves this vulnerability.Fixed in 4.0.0-rc1Patch CVE-2014-0364 - Configuration
Update/adjust ParseRoster so it verifies the From attribute of a roster-query IQ stanza to prevent remote attackers from spoofing IQ responses (CVE-2014-0364).
Smack XMPP API (ParseRoster) Verify From attribute of roster-query IQ stanza = enabled
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2014-0364?
CVE-2014-0364 is classified as a moderate severity vulnerability.
How do I fix CVE-2014-0364?
To fix CVE-2014-0364, you should upgrade the Ignite Realtime Smack library to a version greater than 4.0.0.
Which software is affected by CVE-2014-0364?
CVE-2014-0364 affects the Ignite Realtime Smack versions prior to 4.0.0.
What type of vulnerability is CVE-2014-0364?
CVE-2014-0364 is a vulnerability related to improper handling of XML parsing.
Is there a public exploit for CVE-2014-0364?
There are no known public exploits for CVE-2014-0364 at this time.