First published: Sat Aug 25 2012(Updated: )
Apple iChat Server does not verify that a request was made for an XMPP Server Dialback response, which allows remote XMPP servers to spoof domains via responses for domains that were not asserted.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iChat |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2012-4672 is considered high due to the potential for remote attackers to spoof domains.
To fix CVE-2012-4672, ensure that the XMPP server is updated to the latest version that includes security patches addressing the vulnerability.
CVE-2012-4672 affects Apple iChat Server versions prior to security updates that mitigate this issue.
CVE-2012-4672 can be exploited through domain spoofing by unauthorized remote XMPP servers.
CVE-2012-4672 remains a threat for users running unpatched versions of Apple iChat Server.