Vulnerability Description
The person-to-person secure messaging feature in Sticker before 3.1.0 beta 2 allows remote attackers to post messages to unauthorized private groups by using the group's public encryption key.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Matthew Phillips | Sticker | <= 3.1.0_beta_1 |
References
- http://securitytracker.com/id?1011580Patch
- http://www.osvdb.org/10662Patch
- http://www.securityfocus.com/bid/11333Patch
- http://www.tickertape.org/projects/sticker/release_notes-3.1.0b2.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17664
- http://securitytracker.com/id?1011580Patch
- http://www.osvdb.org/10662Patch
- http://www.securityfocus.com/bid/11333Patch
- http://www.tickertape.org/projects/sticker/release_notes-3.1.0b2.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17664
FAQ
What is CVE-2004-2535?
CVE-2004-2535 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The person-to-person secure messaging feature in Sticker before 3.1.0 beta 2 allows remote attackers to post messages to unauthorized private groups by using the group's public encryption key.
How severe is CVE-2004-2535?
CVE-2004-2535 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2004-2535?
Check the references section above for vendor advisories and patch information. Affected products include: Matthew Phillips Sticker.