CVE-2014-5075
smack: MitM vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The Ignite Realtime Smack XMPP API 4.x before 4.0.2, and 3.x and 2.x when a custom SSLContext is used, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
La API Ignite Realtime Smack XMPP 4.x anterior a 4.0.2, y 3.x y 2.x cuando se utiliza un SSLContext personalizado, no verifica que el nombre del servidor coincide con un nombre de dominio en el campo de asunto Common Name (CN) o subjectAltName del certificado X.509, lo que permite a atacantes man-in-the-middle suplantar los servidores SSL a través de un certificado válido arbitrario.
It was found that SSLSocket in Smack did not perform hostname verification. An attacker could redirect traffic between an application and an XMPP server by providing a valid certificate for a domain under the attacker's control.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-07-24 CVE Reserved
- 2014-08-06 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-310: Cryptographic Issues
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://op-co.de/CVE-2014-5075.html | X_refsource_confirm | |
http://secunia.com/advisories/59915 | Third Party Advisory | |
http://www.securityfocus.com/bid/69064 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://rhn.redhat.com/errata/RHSA-2015-1176.html | 2016-11-28 | |
https://access.redhat.com/security/cve/CVE-2014-5075 | 2015-06-23 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1127276 | 2015-06-23 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Redhat Search vendor "Redhat" | Jboss Fuse Search vendor "Redhat" for product "Jboss Fuse" | <= 6.1.0 Search vendor "Redhat" for product "Jboss Fuse" and version " <= 6.1.0" | - |
Affected
| ||||||
Igniterealtime Search vendor "Igniterealtime" | Smack Api Search vendor "Igniterealtime" for product "Smack Api" | <= 4.0.1 Search vendor "Igniterealtime" for product "Smack Api" and version " <= 4.0.1" | - |
Affected
|