CVE-2016-9928
published 2020-02-06CVE-2016-9928: MCabber before 1.0.4 is vulnerable to roster push attacks, which allows remote attackers to intercept communications, or add themselves as an entity on a 3rd…
PriorityP346high7.4CVSS 3.1
AVNACHPRNUINSUCHIHAN
EPSS
4.51%
90.5th percentile
MCabber before 1.0.4 is vulnerable to roster push attacks, which allows remote attackers to intercept communications, or add themselves as an entity on a 3rd party's roster as another user, which will also garner associated privileges, via crafted XMPP packets.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | mcabber | < mcabber 0.10.2-1.1 (bookworm) | mcabber 0.10.2-1.1 (bookworm) |
| mcabber | mcabber | — | — |
| mcabber | mcabber | >= 0 < 0.10.2-1.1 | 0.10.2-1.1 |
| mcabber | mcabber | >= 0 < 0.10.2-1.1 | 0.10.2-1.1 |
| mcabber | mcabber | >= 0 < 0.10.2-1.1 | 0.10.2-1.1 |
| mcabber | mcabber | >= 0 < 0.10.2-1.1 | 0.10.2-1.1 |
| mcabber | mcabber | >= 0 < 0.10.2-1+deb8u1build0.16.04.1 | 0.10.2-1+deb8u1build0.16.04.1 |
| mcabber | mcabber | >= 1.0.0 < 1.0.4 | 1.0.4 |
CVSS provenance
nvdv3.17.4HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
osv7.4HIGH
vendor_debian7.4HIGH
vendor_ubuntu7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
MCabber vulnerability
vendor_ubuntu·2020-09-16·CVSS 7.4
CVE-2016-9928 [HIGH] MCabber vulnerability
Title: MCabber vulnerability
Summary: MCabber could be made to modify the roster and intercept messages if it
received specially crafted XMPP packets.
It was discovered that MCabber does not properly manage roster pushes. An
attacker could possibly use this issue to remotely perform
machine-in-the-middle attacks. (CVE-2016-9928).
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2016-9928: mcabber - MCabber before 1.0.4 is vulnerable to roster push attacks, which allows remote a...
vendor_debian·2016·CVSS 7.4
CVE-2016-9928 [HIGH] CVE-2016-9928: mcabber - MCabber before 1.0.4 is vulnerable to roster push attacks, which allows remote a...
MCabber before 1.0.4 is vulnerable to roster push attacks, which allows remote attackers to intercept communications, or add themselves as an entity on a 3rd party's roster as another user, which will also garner associated privileges, via crafted XMPP packets.
Scope: local
bookworm: resolved (fixed in 0.10.2-1.1)
bullseye: resolved (fixed in 0.10.2-1.1)
forky: resolved (fixed in 0.10.2-1.1)
sid: resolved (fixed in 0.10.2-1.1)
trixie: resolved (fixed in 0.10.2-1.1)
GHSA
GHSA-q477-8j82-fjq4: MCabber before 1
ghsa_unreviewed·2022-05-24
CVE-2016-9928 [MEDIUM] CWE-269 GHSA-q477-8j82-fjq4: MCabber before 1
MCabber before 1.0.4 is vulnerable to roster push attacks, which allows remote attackers to intercept communications, or add themselves as an entity on a 3rd party's roster as another user, which will also garner associated privileges, via crafted XMPP packets.
OSV
mcabber vulnerability
osv·2020-09-16·CVSS 7.4
CVE-2016-9928 [HIGH] mcabber vulnerability
mcabber vulnerability
It was discovered that MCabber does not properly manage roster pushes. An
attacker could possibly use this issue to remotely perform
machine-in-the-middle attacks. (CVE-2016-9928).
OSV
CVE-2016-9928: MCabber before 1
osv·2020-02-06·CVSS 7.4
CVE-2016-9928 [HIGH] CVE-2016-9928: MCabber before 1
MCabber before 1.0.4 is vulnerable to roster push attacks, which allows remote attackers to intercept communications, or add themselves as an entity on a 3rd party's roster as another user, which will also garner associated privileges, via crafted XMPP packets.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-9928 mcabber: remote attackers can modify the roster and intercept messages via a crafted roster-push IQ stanza
bugzilla·2016-12-12·CVSS 5.4
CVE-2016-9928 [MEDIUM] CVE-2016-9928 mcabber: remote attackers can modify the roster and intercept messages via a crafted roster-push IQ stanza
CVE-2016-9928 mcabber: remote attackers can modify the roster and intercept messages via a crafted roster-push IQ stanza
It was discovered that MCabber versions 1.0.3 and before are vulnerable to an attack identical to Gajim's CVE-2015-8688 that can lead to a malicious actor MITMing a conversation, or adding themselves as an entity on a third parties roster (thereby granting themselves the associated privileges).
Upstream patch:
https://bitbucket.org/McKael/mcabber-crew/commits/6e1ead98930d7dd0a520ad17c720ae4908429033/raw
References:
https://gultsch.de/gajim_roster_push_and_message_interception.html
http://seclists.org/oss-sec/2016/q4/653
Discussion:
Created mcabber tracking bugs for this issue:
Affects: fedora-all [bug 1403792]
---
mcabber 1.0.4 has already arrived to stable in
Bugzilla
CVE-2016-9928 mcabber: remote attackers can modify the roster and intercept messages via a crafted roster-push IQ stanza [fedora-all]
bugzilla·2016-12-12·CVSS 7.4
CVE-2016-9928 [HIGH] CVE-2016-9928 mcabber: remote attackers can modify the roster and intercept messages via a crafted roster-push IQ stanza [fedora-all]
CVE-2016-9928 mcabber: remote attackers can modify the roster and intercept messages via a crafted roster-push IQ stanza [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit messag
http://lists.opensuse.org/opensuse-updates/2017-01/msg00130.htmlhttp://www.openwall.com/lists/oss-security/2016/12/11/2http://www.openwall.com/lists/oss-security/2017/02/09/29http://www.securityfocus.com/bid/94862https://bitbucket.org/McKael/mcabber-crew/commits/6e1ead98930d7dd0a520ad17c720ae4908429033/rawhttps://bugs.debian.org/cgi-bin/bugreport.cgi?bug=845258https://bugzilla.redhat.com/show_bug.cgi?id=1403790https://gultsch.de/gajim_roster_push_and_message_interception.htmlhttps://lists.debian.org/debian-lts-announce/2020/06/msg00031.htmlhttps://usn.ubuntu.com/4506-1/http://lists.opensuse.org/opensuse-updates/2017-01/msg00130.htmlhttp://www.openwall.com/lists/oss-security/2016/12/11/2http://www.openwall.com/lists/oss-security/2017/02/09/29http://www.securityfocus.com/bid/94862https://bitbucket.org/McKael/mcabber-crew/commits/6e1ead98930d7dd0a520ad17c720ae4908429033/rawhttps://bugs.debian.org/cgi-bin/bugreport.cgi?bug=845258https://bugzilla.redhat.com/show_bug.cgi?id=1403790https://gultsch.de/gajim_roster_push_and_message_interception.htmlhttps://lists.debian.org/debian-lts-announce/2020/06/msg00031.htmlhttps://usn.ubuntu.com/4506-1/
2020-02-06
Published