PatchSiren cyber security CVE debrief
CVE-2017-5591 Poezio CVE debrief
CVE-2017-5591 describes an XMPP client trust failure in Message Carbons handling. In affected versions, a remote attacker may cause the application to display messages as if they came from another user, including a contact, which can mislead users and support social engineering. The official NVD data ties the issue to SleekXMPP up to 1.3.1, Slixmpp up to 1.2.3, and Poezio 0.8 through 0.10 as bundled with those libraries.
- Vendor
- Poezio
- Product
- CVE-2017-5591
- CVSS
- MEDIUM 5.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-09
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-09
- Advisory updated
- 2026-05-13
Who should care
Poezio users and deployers, XMPP client maintainers, and security teams responsible for messaging endpoints should review this issue, especially where users rely on displayed sender identity for trust decisions.
Technical summary
The flaw is an incorrect implementation of XEP-0280 Message Carbons. NVD classifies it under CWE-20 and CWE-346 and scores it CVSS 3.1 AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N. The practical impact is integrity loss in the chat UI: a remote party can influence what sender identity the client displays, enabling impersonation-style social engineering without affecting confidentiality or availability.
Defensive priority
Medium. The bug does not indicate code execution or data theft, but it can undermine message authenticity and user trust in a communications client, which is high-value in phishing and impersonation scenarios.
Recommended defensive actions
- Upgrade SleekXMPP to a version newer than 1.3.1 and Slixmpp to a version newer than 1.2.3, or use a Poezio release that bundles patched dependencies.
- If you operate Poezio 0.8, 0.8.1, 0.9, or 0.10, verify the bundled XMPP library versions and confirm they are not in the vulnerable ranges.
- Review message-rendering and Message Carbons handling so the client does not present untrusted carboned messages as if they originated from a different user.
- Where immediate upgrading is not possible, reduce reliance on displayed identity cues for sensitive decisions until patched.
Evidence notes
This debrief is based on the supplied NVD record and referenced advisories/patch links. The source corpus states the affected versions (SleekXMPP <= 1.3.1, Slixmpp <= 1.2.3, Poezio 0.8/0.8.1/0.9/0.10), the issue class (incorrect XEP-0280 implementation), the likely impact (impersonation in the display leading to social engineering), and the NVD CVSS/CWE metadata.
Official resources
-
CVE-2017-5591 CVE record
CVE.org
-
CVE-2017-5591 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Exploit, Mailing List, Third Party Advisory
-
Mitigation or vendor reference
[email protected] - Third Party Advisory, VDB Entry
-
Mitigation or vendor reference
[email protected] - Patch
-
Mitigation or vendor reference
[email protected] - Exploit, Technical Description, Third Party Advisory
-
Mitigation or vendor reference
[email protected] - Exploit, Technical Description, Third Party Advisory
Published 2017-02-09 20:59 UTC in the supplied CVE/NVD data; the source record was last modified 2026-05-13 00:24 UTC.