Apple iChat Server does not verify that a request was made for an XMPP Server Dialback response, which allows remote XMPP servers to spoof domains via responses for domains that were not asserted.
References
Configurations
History
21 Nov 2024, 01:43
Type | Values Removed | Values Added |
---|---|---|
References | () http://xmpp.org/resources/security-notices/server-dialback/ - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/78133 - |
Information
Published : 2012-08-25 16:55
Updated : 2024-11-21 01:43
NVD link : CVE-2012-4672
Mitre link : CVE-2012-4672
CVE.ORG link : CVE-2012-4672
JSON object : View
Products Affected
apple
- ichat_server
CWE
CWE-20
Improper Input Validation