VDB

GCVE-110-MAGEIA-2017-49

GCVE-110-MAGEIA-2017-49
Advisory Published
Vulnetix · Advisory published February 18, 2017
An incorrect implementation of XEP-0280: Message Carbons in Jitsi and other XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks (CVE-2017-5603).

Affected Products

VendorProductVersionsPlatforms
Mageiasubversion0 (affected), 1.9.6-1.mga6 (unaffected)
Mageiajitsi0 (affected), 2.6-1.1.mga5 (unaffected), 0 (affected), 2.6-1.1.mga5 (unaffected)
Mageiasubversion0 (affected), 1.8.18-1.mga5 (unaffected)

Browse GCVE Records

74,108 records in the GCVE database · Updated July 20, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›