CVE-2012-3525
EPSS 2.9%Published: 8/25/2012Modified: 4/28/2026
Also known as:DEBIAN-CVE-2012-3525
Description
s2s/out.c in jabberd2 2.2.16 and earlier does not verify that a request was made for an XMPP Server Dialback response, which allows remote XMPP servers to spoof domains via a (1) Verify Response or (2) Authorization Response.
Affected packages (1)
- Debian/jabberd2from 0, < 2.2.17-1