Lucene search

K
redhatRedHatRHSA-2012:1539
HistoryDec 04, 2012 - 12:00 a.m.

(RHSA-2012:1539) Low: Red Hat Network Proxy server jabberd security update

2012-12-0400:00:00
access.redhat.com
17

0.005 Low

EPSS

Percentile

77.2%

This package provides jabberd 2, an Extensible Messaging and Presence
Protocol (XMPP) server used for XML based communication.

It was discovered that the XMPP Dialback protocol implementation in
jabberd 2 did not properly validate Verify Response and Authorization
Response messages. A remote attacker able to connect to the jabberd’s
server-to-server communication port could possibly use this flaw to spoof
source domains of the XMPP messages. (CVE-2012-3525)

Users of Red Hat Network Proxy 5.5 are advised to upgrade to this updated
jabberd package, which resolves this issue. For this update to take effect,
Red Hat Network Proxy must be restarted. Refer to the Solution section for
details.