jabberd2 before 2.2.14 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
The product uses XML documents and allows their structure to be defined with a Document Type Definition (DTD), but it does not properly control the number of recursive definitions of entities.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Jabberd2 | Jabberd2 | * | 2.2.14 (excluding) |
Red Hat Network Proxy v 5.4 | RedHat | jabberd-0:2.2.8-12.el5sat | * |
Red Hat Network Satellite Server v 5.4 | RedHat | jabberd-0:2.2.8-12.el5sat | * |
Jabberd2 | Ubuntu | dapper | * |
Jabberd2 | Ubuntu | devel | * |
Jabberd2 | Ubuntu | hardy | * |
Jabberd2 | Ubuntu | lucid | * |
Jabberd2 | Ubuntu | maverick | * |
Jabberd2 | Ubuntu | natty | * |
Jabberd2 | Ubuntu | upstream | * |