fritzy / SleekXMPP

Python 2.6+/3.1+ XMPP Library
http://groups.google.com/group/sleekxmpp-discussion
Other
1.1k stars 299 forks source link

CVE-2017-5589+ Multiple XMPP Clients User Impersonation Vulnerability #442

Closed Neustradamus closed 7 years ago

Neustradamus commented 7 years ago

https://rt-solutions.de/en/2017/02/CVE-2017-5589_xmpp_carbons/

sandrotosi commented 7 years ago

Hello, this bug will prevent SleekXMPP to be released with the upcoming debian stable release (codename stretch) - could you please have a look at this asap?

thanks!!

carnil commented 7 years ago

The specific CVE assigned is CVE-2017-5591

bear commented 7 years ago

closing - it's in v1.3.2 and also in develop branch