PT-2012-5538 · Psyced · Psyced
Published
2012-08-25
·
Updated
2012-08-27
·
CVE-2012-4671
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
psyced versions prior to 20120821
Description
The issue allows remote XMPP servers to spoof domains via responses for domains that were not asserted, due to a lack of verification that a request was made for an XMPP Server Dialback response.
Recommendations
For versions prior to 20120821, update to a version that includes the fix for this issue to prevent domain spoofing.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Psyced