modules/xmpp/serv_xmpp.c in Citadel 7.86 and earlier does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Citadel | Citadel | 7.84 | 7.84 |
Citadel | Citadel | 7.81 | 7.81 |
Citadel | Citadel | 7.80 | 7.80 |
Citadel | Citadel | 7.82 | 7.82 |
Citadel | Citadel | 7.50 | 7.50 |
Citadel | Citadel | * | 7.86 |
Citadel | Citadel | 7.11 | 7.11 |
Citadel | Citadel | 7.60 | 7.60 |