jabberd14 1.6.1.1 and earlier does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Jabberd14 | Jabberd | * | 1.6.1.1 (including) |
Jabberd14 | Jabberd | 1.4.1 (including) | 1.4.1 (including) |
Jabberd14 | Jabberd | 1.4.2 (including) | 1.4.2 (including) |
Jabberd14 | Jabberd | 1.4.3 (including) | 1.4.3 (including) |
Jabberd14 | Jabberd | 1.4.3.1 (including) | 1.4.3.1 (including) |
Jabberd14 | Jabberd | 1.4.4 (including) | 1.4.4 (including) |
Jabberd14 | Jabberd | 1.6.0 (including) | 1.6.0 (including) |
Jabberd14 | Jabberd | 1.6.1 (including) | 1.6.1 (including) |
Jabberd14 | Ubuntu | lucid | * |
Jabberd14 | Ubuntu | maverick | * |
Jabberd14 | Ubuntu | natty | * |
Jabberd14 | Ubuntu | upstream | * |