modules/xmpp/serv_xmpp.c in Citadel 7.86 and earlier does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Citadel | Citadel | * | 7.86 (including) |
Citadel | Citadel | 7.11 (including) | 7.11 (including) |
Citadel | Citadel | 7.50 (including) | 7.50 (including) |
Citadel | Citadel | 7.60 (including) | 7.60 (including) |
Citadel | Citadel | 7.80 (including) | 7.80 (including) |
Citadel | Citadel | 7.81 (including) | 7.81 (including) |
Citadel | Citadel | 7.82 (including) | 7.82 (including) |
Citadel | Citadel | 7.84 (including) | 7.84 (including) |
Citadel | Ubuntu | artful | * |
Citadel | Ubuntu | lucid | * |
Citadel | Ubuntu | maverick | * |
Citadel | Ubuntu | natty | * |
Citadel | Ubuntu | oneiric | * |
Citadel | Ubuntu | precise | * |
Citadel | Ubuntu | quantal | * |
Citadel | Ubuntu | raring | * |
Citadel | Ubuntu | saucy | * |
Citadel | Ubuntu | upstream | * |
Citadel | Ubuntu | utopic | * |
Citadel | Ubuntu | vivid | * |
Citadel | Ubuntu | wily | * |
Citadel | Ubuntu | yakkety | * |
Citadel | Ubuntu | zesty | * |