CVE-2011-1755

jabberd2 before 2.2.14 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:jabber:jabberd2:2.2.10:*:*:*:*:*:*:*
cpe:2.3:a:jabber:jabberd2:2.2.9:*:*:*:*:*:*:*
cpe:2.3:a:jabber:jabberd2:2.2.3:*:*:*:*:*:*:*
cpe:2.3:a:jabber:jabberd2:2.2.2:*:*:*:*:*:*:*
cpe:2.3:a:jabber:jabberd2:2.1.19:*:*:*:*:*:*:*
cpe:2.3:a:jabber:jabberd2:2.1.18:*:*:*:*:*:*:*
cpe:2.3:a:jabber:jabberd2:2.1.11:*:*:*:*:*:*:*
cpe:2.3:a:jabber:jabberd2:2.1.10:*:*:*:*:*:*:*
cpe:2.3:a:jabber:jabberd2:2.1.3:*:*:*:*:*:*:*
cpe:2.3:a:jabber:jabberd2:2.1.2:*:*:*:*:*:*:*
cpe:2.3:a:jabber:jabberd2:2.2.12:*:*:*:*:*:*:*
cpe:2.3:a:jabber:jabberd2:2.2.7:*:*:*:*:*:*:*
cpe:2.3:a:jabber:jabberd2:*:*:*:*:*:*:*:*
cpe:2.3:a:jabber:jabberd2:2.2.0:*:*:*:*:*:*:*
cpe:2.3:a:jabber:jabberd2:2.1.12:*:*:*:*:*:*:*
cpe:2.3:a:jabber:jabberd2:2.1.21:*:*:*:*:*:*:*
cpe:2.3:a:jabber:jabberd2:2.1.15:*:*:*:*:*:*:*
cpe:2.3:a:jabber:jabberd2:2.2.11:*:*:*:*:*:*:*
cpe:2.3:a:jabber:jabberd2:2.1.5:*:*:*:*:*:*:*
cpe:2.3:a:jabber:jabberd2:2.1.20:*:*:*:*:*:*:*
cpe:2.3:a:jabber:jabberd2:2.2.5:*:*:*:*:*:*:*
cpe:2.3:a:jabber:jabberd2:2.2.7.1:*:*:*:*:*:*:*
cpe:2.3:a:jabber:jabberd2:2.1.22:*:*:*:*:*:*:*
cpe:2.3:a:jabber:jabberd2:2.1.14:*:*:*:*:*:*:*
cpe:2.3:a:jabber:jabberd2:2.1.23:*:*:*:*:*:*:*
cpe:2.3:a:jabber:jabberd2:2.2.1:*:*:*:*:*:*:*
cpe:2.3:a:jabber:jabberd2:2.1.4:*:*:*:*:*:*:*
cpe:2.3:a:jabber:jabberd2:2.1.7:*:*:*:*:*:*:*
cpe:2.3:a:jabber:jabberd2:2.2.8:*:*:*:*:*:*:*
cpe:2.3:a:jabber:jabberd2:2.2.6:*:*:*:*:*:*:*
cpe:2.3:a:jabber:jabberd2:2.1.13:*:*:*:*:*:*:*
cpe:2.3:a:jabber:jabberd2:2.1.6:*:*:*:*:*:*:*
cpe:2.3:a:jabber:jabberd2:2.2.4:*:*:*:*:*:*:*
cpe:2.3:a:jabber:jabberd2:2.1:*:*:*:*:*:*:*
cpe:2.3:a:jabber:jabberd2:2.1.8:*:*:*:*:*:*:*
cpe:2.3:a:jabber:jabberd2:2.1.24:*:*:*:*:*:*:*
cpe:2.3:a:jabber:jabberd2:2.1.1:*:*:*:*:*:*:*
cpe:2.3:a:jabber:jabberd2:2.1.17:*:*:*:*:*:*:*
cpe:2.3:a:jabber:jabberd2:2.1.16:*:*:*:*:*:*:*
cpe:2.3:a:jabber:jabberd2:2.1.9:*:*:*:*:*:*:*

Information

Published : 2011-06-20 19:52

Updated : 2017-08-16 18:34


NVD link : CVE-2011-1755

Mitre link : CVE-2011-1755


JSON object : View

CWE
CWE-399

Resource Management Errors

Advertisement

dedicated server usa

Products Affected

jabber

  • jabberd2