CVE-2016-9928: Canonical Ubuntu Linux

High severity, CVSS 7.4. EPSS: 4.5% chance of exploitation in the next 30 days.

MCabber before 1.0.4 is vulnerable to roster push attacks, which allows remote attackers to intercept communications, or add themselves as an entity on a 3rd party's roster as another user, which will also garner associated privileges, via crafted XMPP packets.

Affected products

  • Canonical Ubuntu Linux: version 16.04 only
  • Debian Debian Linux: version 8.0 only
  • Mcabber Mcabber: from 1.0.0, before 1.0.4 (fixed in 1.0.4)

Published 2020-02-06. Last modified 2026-06-17.