CVE-2011-2205

Prosody before 0.8.1 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:prosody:prosody:0.6.1:*:*:*:*:*:*:*
cpe:2.3:a:prosody:prosody:0.5.1:*:*:*:*:*:*:*
cpe:2.3:a:prosody:prosody:0.2.0:*:*:*:*:*:*:*
cpe:2.3:a:prosody:prosody:0.1.0:*:*:*:*:*:*:*
cpe:2.3:a:prosody:prosody:0.7:*:*:*:*:*:*:*
cpe:2.3:a:prosody:prosody:0.6:*:*:*:*:*:*:*
cpe:2.3:a:prosody:prosody:0.4.2:*:*:*:*:*:*:*
cpe:2.3:a:prosody:prosody:0.4.1:*:*:*:*:*:*:*
cpe:2.3:a:prosody:prosody:0.7.0:*:*:*:*:*:*:*
cpe:2.3:a:prosody:prosody:0.6.0:*:*:*:*:*:*:*
cpe:2.3:a:prosody:prosody:0.4.0:*:*:*:*:*:*:*
cpe:2.3:a:prosody:prosody:0.8:*:*:*:*:*:*:*
cpe:2.3:a:prosody:prosody:0.5.0:*:*:*:*:*:*:*
cpe:2.3:a:prosody:prosody:0.5.2:*:*:*:*:*:*:*
cpe:2.3:a:prosody:prosody:0.3.0:*:*:*:*:*:*:*
cpe:2.3:a:prosody:prosody:*:*:*:*:*:*:*:*

Information

Published : 2011-06-22 14:55

Updated : 2017-08-28 18:29


NVD link : CVE-2011-2205

Mitre link : CVE-2011-2205


JSON object : View

CWE
CWE-399

Resource Management Errors

Advertisement

dedicated server usa

Products Affected

prosody

  • prosody