CVE-2014-0364
Ignite Realtime Smack XMPP API <4.0.0-rc1 - Info Disclosure
Title source: llmDescription
The ParseRoster component in the Ignite Realtime Smack XMPP API before 4.0.0-rc1 does not verify the from attribute of a roster-query IQ stanza, which allows remote attackers to spoof IQ responses via a crafted attribute.
References (6)
Core 6
Core References
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/59291
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/59290
Third Party Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2015-1176.html
Third Party Advisory, US Government Resource third-party-advisory
x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/489228
Vendor Advisory x_refsource_confirm
http://community.igniterealtime.org/blogs/ignite/2014/04/17/asmack-400-rc1-has-been-released
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/67124
Scores
EPSS
0.0624
EPSS Percentile
92.6%
Details
CWE
CWE-345
Status
published
Products (1)
igniterealtime/smack
< 4.0.0
Published
Apr 30, 2014
Tracked Since
Feb 18, 2026