CVE-2012-3525

s2s/out.c in jabberd2 2.2.16 and earlier does not verify that a request was made for an XMPP Server Dialback response, which allows remote XMPP servers to spoof domains via a (1) Verify Response or (2) Authorization Response.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:jabber2:jabberd2:2.1.19:*:*:*:*:*:*:*
cpe:2.3:a:jabberd2:jabberd2:*:*:*:*:*:*:*:*
cpe:2.3:a:jabberd2:jabberd2:2.1:*:*:*:*:*:*:*
cpe:2.3:a:jabberd2:jabberd2:2.1.1:*:*:*:*:*:*:*
cpe:2.3:a:jabberd2:jabberd2:2.1.2:*:*:*:*:*:*:*
cpe:2.3:a:jabberd2:jabberd2:2.1.3:*:*:*:*:*:*:*
cpe:2.3:a:jabberd2:jabberd2:2.1.4:*:*:*:*:*:*:*
cpe:2.3:a:jabberd2:jabberd2:2.1.5:*:*:*:*:*:*:*
cpe:2.3:a:jabberd2:jabberd2:2.1.6:*:*:*:*:*:*:*
cpe:2.3:a:jabberd2:jabberd2:2.1.7:*:*:*:*:*:*:*
cpe:2.3:a:jabberd2:jabberd2:2.1.8:*:*:*:*:*:*:*
cpe:2.3:a:jabberd2:jabberd2:2.1.9:*:*:*:*:*:*:*
cpe:2.3:a:jabberd2:jabberd2:2.1.10:*:*:*:*:*:*:*
cpe:2.3:a:jabberd2:jabberd2:2.1.11:*:*:*:*:*:*:*
cpe:2.3:a:jabberd2:jabberd2:2.1.12:*:*:*:*:*:*:*
cpe:2.3:a:jabberd2:jabberd2:2.1.13:*:*:*:*:*:*:*
cpe:2.3:a:jabberd2:jabberd2:2.1.14:*:*:*:*:*:*:*
cpe:2.3:a:jabberd2:jabberd2:2.1.15:*:*:*:*:*:*:*
cpe:2.3:a:jabberd2:jabberd2:2.1.16:*:*:*:*:*:*:*
cpe:2.3:a:jabberd2:jabberd2:2.1.17:*:*:*:*:*:*:*
cpe:2.3:a:jabberd2:jabberd2:2.1.18:*:*:*:*:*:*:*
cpe:2.3:a:jabberd2:jabberd2:2.1.20:*:*:*:*:*:*:*
cpe:2.3:a:jabberd2:jabberd2:2.1.21:*:*:*:*:*:*:*
cpe:2.3:a:jabberd2:jabberd2:2.1.22:*:*:*:*:*:*:*
cpe:2.3:a:jabberd2:jabberd2:2.1.23:*:*:*:*:*:*:*
cpe:2.3:a:jabberd2:jabberd2:2.1.24:*:*:*:*:*:*:*
cpe:2.3:a:jabberd2:jabberd2:2.2.0:*:*:*:*:*:*:*
cpe:2.3:a:jabberd2:jabberd2:2.2.1:*:*:*:*:*:*:*
cpe:2.3:a:jabberd2:jabberd2:2.2.2:*:*:*:*:*:*:*
cpe:2.3:a:jabberd2:jabberd2:2.2.3:*:*:*:*:*:*:*
cpe:2.3:a:jabberd2:jabberd2:2.2.4:*:*:*:*:*:*:*
cpe:2.3:a:jabberd2:jabberd2:2.2.5:*:*:*:*:*:*:*
cpe:2.3:a:jabberd2:jabberd2:2.2.6:*:*:*:*:*:*:*
cpe:2.3:a:jabberd2:jabberd2:2.2.7:*:*:*:*:*:*:*
cpe:2.3:a:jabberd2:jabberd2:2.2.7.1:*:*:*:*:*:*:*
cpe:2.3:a:jabberd2:jabberd2:2.2.8:*:*:*:*:*:*:*
cpe:2.3:a:jabberd2:jabberd2:2.2.9:*:*:*:*:*:*:*
cpe:2.3:a:jabberd2:jabberd2:2.2.10:*:*:*:*:*:*:*
cpe:2.3:a:jabberd2:jabberd2:2.2.11:*:*:*:*:*:*:*
cpe:2.3:a:jabberd2:jabberd2:2.2.12:*:*:*:*:*:*:*
cpe:2.3:a:jabberd2:jabberd2:2.2.13:*:*:*:*:*:*:*
cpe:2.3:a:jabberd2:jabberd2:2.2.14:*:*:*:*:*:*:*
cpe:2.3:a:jabberd2:jabberd2:2.2.15:*:*:*:*:*:*:*

History

21 Nov 2024, 01:41

Type Values Removed Values Added
References () http://lists.apple.com/archives/security-announce/2013/Mar/msg00002.html - () http://lists.apple.com/archives/security-announce/2013/Mar/msg00002.html -
References () http://rhn.redhat.com/errata/RHSA-2012-1538.html - () http://rhn.redhat.com/errata/RHSA-2012-1538.html -
References () http://rhn.redhat.com/errata/RHSA-2012-1539.html - () http://rhn.redhat.com/errata/RHSA-2012-1539.html -
References () http://secunia.com/advisories/50124 - Vendor Advisory () http://secunia.com/advisories/50124 - Vendor Advisory
References () http://secunia.com/advisories/50859 - () http://secunia.com/advisories/50859 -
References () http://www.mail-archive.com/jabberd2%40lists.xiaoka.com/msg01903.html - () http://www.mail-archive.com/jabberd2%40lists.xiaoka.com/msg01903.html -
References () http://www.openwall.com/lists/oss-security/2012/08/22/5 - () http://www.openwall.com/lists/oss-security/2012/08/22/5 -
References () http://www.openwall.com/lists/oss-security/2012/08/22/6 - () http://www.openwall.com/lists/oss-security/2012/08/22/6 -
References () http://www.securityfocus.com/bid/55167 - () http://www.securityfocus.com/bid/55167 -
References () http://xmpp.org/resources/security-notices/server-dialback/ - Vendor Advisory () http://xmpp.org/resources/security-notices/server-dialback/ - Vendor Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=850872 - () https://bugzilla.redhat.com/show_bug.cgi?id=850872 -
References () https://github.com/Jabberd2/jabberd2/commit/aabcffae560d5fd00cd1d2ffce5d760353cf0a4d - Exploit, Patch () https://github.com/Jabberd2/jabberd2/commit/aabcffae560d5fd00cd1d2ffce5d760353cf0a4d - Exploit, Patch

Information

Published : 2012-08-25 16:55

Updated : 2024-11-21 01:41


NVD link : CVE-2012-3525

Mitre link : CVE-2012-3525

CVE.ORG link : CVE-2012-3525


JSON object : View

Products Affected

jabberd2

  • jabberd2

jabber2

  • jabberd2
CWE
CWE-20

Improper Input Validation