An incorrect implementation of XEP-0280: Message Carbons[0] in psi-plus client allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks. References: http://seclists.org/oss-sec/2017/q1/373 Upstream patch: https://github.com/psi-im/iris/pull/47/commits/02e976d4426a1319a7af7d26d7aba9d8c6077570
Created psi-plus tracking bugs for this issue: Affects: epel-7 [bug 1421070] Affects: fedora-all [bug 1421071]
psi-plus in Fedora hasn't carbon feature.