CVE Vulnerabilities

CVE-2014-2745

Published: Apr 11, 2014 | Modified: Apr 19, 2014
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.8 HIGH
AV:N/AC:L/Au:N/C:N/I:N/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Prosody before 0.9.4 does not properly restrict the processing of compressed XML elements, which allows remote attackers to cause a denial of service (resource consumption) via a crafted XMPP stream, aka an xmppbomb attack, related to core/portmanager.lua and util/xmppstream.lua.

Affected Software

Name Vendor Start Version End Version
Prosody Prosody * 0.9.3 (including)
Prosody Prosody 0.1.0 (including) 0.1.0 (including)
Prosody Prosody 0.2.0 (including) 0.2.0 (including)
Prosody Prosody 0.3.0 (including) 0.3.0 (including)
Prosody Prosody 0.4.0 (including) 0.4.0 (including)
Prosody Prosody 0.4.1 (including) 0.4.1 (including)
Prosody Prosody 0.4.2 (including) 0.4.2 (including)
Prosody Prosody 0.5.0 (including) 0.5.0 (including)
Prosody Prosody 0.5.1 (including) 0.5.1 (including)
Prosody Prosody 0.5.2 (including) 0.5.2 (including)
Prosody Prosody 0.6.0 (including) 0.6.0 (including)
Prosody Prosody 0.6.1 (including) 0.6.1 (including)
Prosody Prosody 0.6.2 (including) 0.6.2 (including)
Prosody Prosody 0.7.0 (including) 0.7.0 (including)
Prosody Prosody 0.8.0 (including) 0.8.0 (including)
Prosody Prosody 0.8.1 (including) 0.8.1 (including)
Prosody Prosody 0.8.2 (including) 0.8.2 (including)
Prosody Prosody 0.9.0 (including) 0.9.0 (including)
Prosody Prosody 0.9.1 (including) 0.9.1 (including)
Prosody Prosody 0.9.2 (including) 0.9.2 (including)
Prosody Ubuntu lucid *
Prosody Ubuntu precise *
Prosody Ubuntu quantal *
Prosody Ubuntu saucy *
Prosody Ubuntu trusty *
Prosody Ubuntu upstream *

References