Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The ParseRoster component in the Ignite Realtime Smack XMPP API before 4.0.0-rc1 does not verify the from attribute of a roster-query IQ stanza, which allows remote attackers to spoof IQ responses via a crafted attribute.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Ignite Realtime Smack XMPP API ParseRoster组件安全漏洞
Vulnerability Description
Ignite Realtime Smack XMPP API是IgniteRealtime社区的一个开源的XMPP(前称Jabber,即时通讯软件)客户端库。 Ignite Realtime Smack XMPP API 4.0.0:snapshot-2014-04-15及之前版本的ParseRoster组件中存在安全漏洞,该漏洞源于程序没有正确验证roster-query的‘from’属性。远程攻击者可借助特制的属性利用该漏洞实施中间人攻击,欺骗IQ响应。
CVSS Information
N/A
Vulnerability Type
N/A