Release date:
Updated on:
Affected Systems:
Apple iChat Server
Description:
--------------------------------------------------------------------------------
Bugtraq id: 55294
Cve id: CVE-2012-4672
Apple iChat Server is a timely communication component of Mac OS X Server.
The XMPP Server Dialback protocol (RFC 3920/XEP-0220) used by Apple's iChat Server does not verify whether a request responds to the XMPP Server's callback through a domain without assertions, remote XMPP server spoofing domain is allowed.
<* Source: Philipp Hancke
Link: http://xmpp.org/resources/security-notices/server-dialback/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Apple
-----
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://support.apple.com/