5.8
CVSSv2

CVE-2012-3525

Published: 25/08/2012 Updated: 13/02/2023
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

s2s/out.c in jabberd2 2.2.16 and previous versions does not verify that a request was made for an XMPP Server Dialback response, which allows remote XMPP servers to spoof domains via a (1) Verify Response or (2) Authorization Response.

Vulnerable Product Search on Vulmon Subscribe to Product

jabberd2 jabberd2 2.1.2

jabberd2 jabberd2 2.1.9

jabberd2 jabberd2 2.1.23

jabberd2 jabberd2 2.2.7.1

jabberd2 jabberd2 2.1.1

jabberd2 jabberd2 2.1.5

jabberd2 jabberd2 2.2.10

jabberd2 jabberd2 2.2.0

jabberd2 jabberd2 2.1.8

jabberd2 jabberd2 2.2.2

jabberd2 jabberd2 2.1.12

jabberd2 jabberd2 2.2.8

jabberd2 jabberd2 2.1.18

jabberd2 jabberd2 2.1.22

jabberd2 jabberd2

jabberd2 jabberd2 2.2.7

jabberd2 jabberd2 2.2.5

jabberd2 jabberd2 2.2.13

jabberd2 jabberd2 2.1.10

jabberd2 jabberd2 2.1

jabberd2 jabberd2 2.1.15

jabberd2 jabberd2 2.2.15

jabberd2 jabberd2 2.2.1

jabberd2 jabberd2 2.1.11

jabberd2 jabberd2 2.1.4

jabberd2 jabberd2 2.1.17

jabberd2 jabberd2 2.2.12

jabberd2 jabberd2 2.1.7

jabberd2 jabberd2 2.1.20

jabberd2 jabberd2 2.2.3

jabber2 jabberd2 2.1.19

jabberd2 jabberd2 2.1.24

jabberd2 jabberd2 2.1.16

jabberd2 jabberd2 2.1.14

jabberd2 jabberd2 2.2.6

jabberd2 jabberd2 2.2.9

jabberd2 jabberd2 2.1.6

jabberd2 jabberd2 2.2.11

jabberd2 jabberd2 2.1.3

jabberd2 jabberd2 2.2.4

jabberd2 jabberd2 2.1.13

jabberd2 jabberd2 2.1.21

jabberd2 jabberd2 2.2.14

Vendor Advisories

Debian Bug report logs - #685666 jabberd2: CVE-2012-3525 Package: jabberd2; Maintainer for jabberd2 is Debian XMPP Maintainers <pkg-xmpp-devel@listsaliothdebianorg>; Source for jabberd2 is src:jabberd2 (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Thu, 23 Aug 2012 07:51:02 UTC Sever ...
Synopsis Low: Red Hat Network Proxy server jabberd security update Type/Severity Security Advisory: Low Topic An updated jabberd package that fixes one security issue is now availablefor Red Hat Network Proxy 55 for Red Hat Enterprise Linux 5 and 6The Red Hat Security Response Team has rated this update a ...
Synopsis Low: Red Hat Network Satellite server jabberd security update Type/Severity Security Advisory: Low Topic An updated jabberd package that fixes one security issue is now availablefor Red Hat Network Satellite 55 for Red Hat Enterprise Linux 5 and 6The Red Hat Security Response Team has rated this ...