FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2009-1595

This CVE name corresponds to:

Entered Topic
2008-11-19 openfire -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2009-1595
Phase Assigned(20090511)

Description

The jabber:iq:auth implementation in IQAuthHandler.java in Ignite Realtime Openfire before 3.6.4 allows remote authenticated users to change the passwords of arbitrary accounts via a modified username element in a passwd_change action.

References

Source Reference
CONFIRM http://www.igniterealtime.org/builds/openfire/docs/latest/changelog.html
CONFIRM http://www.igniterealtime.org/community/message/190280
CONFIRM http://www.igniterealtime.org/issues/browse/JM-1531
BID 34804
OSVDB 54189
SECUNIA 34976
VUPEN ADV-2009-1237
XF openfire-jabberiqauth-security-bypass(50292)