REDHAT-BUG-1093276: Medium severity Ignite Realtime Smack XMPP API vulnerability
Common Vulnerabilities and Exposures assigned an identifier CVE-2014-0364 to the following vulnerability:
Name: CVE-2014-0364 URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0364 Assigned: 20131205 Reference: http://community.igniterealtime.org/blogs/ignite/2014/04/17/asmack-400-rc1-has-been-released Reference: CERT-VN:VU#489228 Reference: http://www.kb.cert.org/vuls/id/489228
The ParseRoster component in the Ignite Realtime Smack XMPP API before 4.0.0-rc1 does not verify the from attribute of a roster-query IQ stanza, which allows remote attackers to spoof IQ responses via a crafted attribute.
It is not clear whether this flaw affects the version of smack in Fedora. Both of these look to be needed to complete the fix:
http://issues.igniterealtime.org/browse/SMACK-533 http://issues.igniterealtime.org/browse/SMACK-538
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1093276?
The severity of REDHAT-BUG-1093276 is classified as moderate due to potential impacts on confidentiality and integrity.
How do I fix REDHAT-BUG-1093276?
To fix REDHAT-BUG-1093276, you should upgrade to the latest version of Ignite Realtime Smack XMPP API that is higher than 4.0.0-rc1.
What are the potential impacts of REDHAT-BUG-1093276?
The potential impacts of REDHAT-BUG-1093276 include unauthorized access to sensitive data due to a flaw in the XMPP API.
Is REDHAT-BUG-1093276 present in earlier versions of the software?
Yes, REDHAT-BUG-1093276 is present in Ignite Realtime Smack XMPP API versions prior to 4.0.0-rc1.
When was REDHAT-BUG-1093276 disclosed?
REDHAT-BUG-1093276 was disclosed on April 17, 2014.