CVE-2012-3525: JABBER2 JABBERD2

Medium severity, CVSS 5.8. EPSS: 1.7% chance of exploitation in the next 30 days.

s2s/out.c in jabberd2 2.2.16 and earlier does not verify that a request was made for an XMPP Server Dialback response, which allows remote XMPP servers to spoof domains via a (1) Verify Response or (2) Authorization Response.

Affected products

  • JABBER2 JABBERD2: version 2.1.19 only
  • JABBERD2 JABBERD2: up to and including 2.2.16; version 2.1 only; version 2.1.1 only; version 2.1.2 only; version 2.1.3 only; version 2.1.4 only; …

Published 2012-08-25. Last modified 2026-06-16.