UbuntuUpdates.org

Package "jabberd2"

Name: jabberd2

Description:

Jabber instant messenger server

Latest version: 2.2.8-2.2ubuntu0.12.04.1
Release: precise (12.04)
Level: security
Repository: universe
Homepage: http://jabberd2.xiaoka.com/

Links


Download "jabberd2"


Other versions of "jabberd2" in Precise

Repository Area Version
base universe 2.2.8-2.2build1
updates universe 2.2.8-2.2ubuntu0.12.04.1

Changelog

Version: 2.2.8-2.2ubuntu0.12.04.1 2012-11-06 19:06:49 UTC

  jabberd2 (2.2.8-2.2ubuntu0.12.04.1) precise-security; urgency=low

  * SECURITY UPDATE: Fixed possibility of Unsolicited Dialback Attacks
    - debian/patches/CVE-2012-3525.dpatch: check Verify Response and
      Authorization Response in s2s sessions
    - CVE-2012-3525
 -- Jamie Strandboge <email address hidden> Thu, 23 Aug 2012 08:07:18 -0500

CVE-2012-3525 s2s/out.c in jabberd2 2.2.16 and earlier does not verify that a request was made for an XMPP Server Dialback response, which allows remote XMPP serve



About   -   Send Feedback to @ubuntu_updates