CVE-2014-0364
published 2014-04-30CVE-2014-0364: The ParseRoster component in the Ignite Realtime Smack XMPP API before 4.0.0-rc1 does not verify the from attribute of a roster-query IQ stanza, which allows…
PriorityP432medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
6.24%
92.8th percentile
The ParseRoster component in the Ignite Realtime Smack XMPP API before 4.0.0-rc1 does not verify the from attribute of a roster-query IQ stanza, which allows remote attackers to spoof IQ responses via a crafted attribute.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| igniterealtime | smack | < 4.0.0 | 4.0.0 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5xpq-f27x-7pw7: The ParseRoster component in the Ignite Realtime Smack XMPP API before 4
ghsa_unreviewed·2022-05-13
CVE-2014-0364 [MEDIUM] CWE-345 GHSA-5xpq-f27x-7pw7: The ParseRoster component in the Ignite Realtime Smack XMPP API before 4
The ParseRoster component in the Ignite Realtime Smack XMPP API before 4.0.0-rc1 does not verify the from attribute of a roster-query IQ stanza, which allows remote attackers to spoof IQ responses via a crafted attribute.
Red Hat
smack: IQ response spoofing
vendor_redhat·2014-01-31·CVSS 5.0
CVE-2014-0364 [MEDIUM] smack: IQ response spoofing
smack: IQ response spoofing
The ParseRoster component in the Ignite Realtime Smack XMPP API before 4.0.0-rc1 does not verify the from attribute of a roster-query IQ stanza, which allows remote attackers to spoof IQ responses via a crafted attribute.
It was found that the ParseRoster component in the Smack XMPP API did not verify the From attribute of a roster-query IQ stanza. A remote attacker could use this flaw to spoof IQ responses.
Package: smack (Red Hat JBoss BRMS 5) - Will not fix
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-0364 smack: IQ response spoofing
bugzilla·2014-05-01·CVSS 5.0
CVE-2014-0364 [MEDIUM] CVE-2014-0364 smack: IQ response spoofing
CVE-2014-0364 smack: IQ response spoofing
Common Vulnerabilities and Exposures assigned an identifier CVE-2014-0364 to
the following vulnerability:
Name: CVE-2014-0364
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0364
Assigned: 20131205
Reference: http://community.igniterealtime.org/blogs/ignite/2014/04/17/asmack-400-rc1-has-been-released
Reference: CERT-VN:VU#489228
Reference: http://www.kb.cert.org/vuls/id/489228
The ParseRoster component in the Ignite Realtime Smack XMPP API before
4.0.0-rc1 does not verify the from attribute of a roster-query IQ
stanza, which allows remote attackers to spoof IQ responses via a
crafted attribute.
It is not clear whether this flaw affects the version of smack in Fedora. Both of these look to be needed to complete the fix:
http://issue
Bugzilla
CVE-2014-0364 smack: IQ response spoofing [fedora-all]
bugzilla·2014-05-01·CVSS 5.0
CVE-2014-0364 [MEDIUM] CVE-2014-0364 smack: IQ response spoofing [fedora-all]
CVE-2014-0364 smack: IQ response spoofing [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
NOTE: this issue affects multiple supported versions of F
http://community.igniterealtime.org/blogs/ignite/2014/04/17/asmack-400-rc1-has-been-releasedhttp://rhn.redhat.com/errata/RHSA-2015-1176.htmlhttp://secunia.com/advisories/59290http://secunia.com/advisories/59291http://www.kb.cert.org/vuls/id/489228http://www.securityfocus.com/bid/67124http://community.igniterealtime.org/blogs/ignite/2014/04/17/asmack-400-rc1-has-been-releasedhttp://rhn.redhat.com/errata/RHSA-2015-1176.htmlhttp://secunia.com/advisories/59290http://secunia.com/advisories/59291http://www.kb.cert.org/vuls/id/489228http://www.securityfocus.com/bid/67124
2014-04-30
Published