5
CVSSv2

CVE-2014-0364

Published: 30/04/2014 Updated: 23/02/2021
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

The ParseRoster component in the Ignite Realtime Smack XMPP API prior to 4.0.0-rc1 does not verify the from attribute of a roster-query IQ stanza, which allows remote malicious users to spoof IQ responses via a crafted attribute.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

igniterealtime smack

Vendor Advisories

It was found that the ParseRoster component in the Smack XMPP API did not verify the From attribute of a roster-query IQ stanza A remote attacker could use this flaw to spoof IQ responses ...