CVE Vulnerabilities

CVE-2014-2745

Published: Apr 11, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.8 HIGH
AV:N/AC:L/Au:N/C:N/I:N/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Prosody before 0.9.4 does not properly restrict the processing of compressed XML elements, which allows remote attackers to cause a denial of service (resource consumption) via a crafted XMPP stream, aka an xmppbomb attack, related to core/portmanager.lua and util/xmppstream.lua.

Affected Software

NameVendorStart VersionEnd Version
ProsodyProsody*0.9.3 (including)
ProsodyProsody0.1.0 (including)0.1.0 (including)
ProsodyProsody0.2.0 (including)0.2.0 (including)
ProsodyProsody0.3.0 (including)0.3.0 (including)
ProsodyProsody0.4.0 (including)0.4.0 (including)
ProsodyProsody0.4.1 (including)0.4.1 (including)
ProsodyProsody0.4.2 (including)0.4.2 (including)
ProsodyProsody0.5.0 (including)0.5.0 (including)
ProsodyProsody0.5.1 (including)0.5.1 (including)
ProsodyProsody0.5.2 (including)0.5.2 (including)
ProsodyProsody0.6.0 (including)0.6.0 (including)
ProsodyProsody0.6.1 (including)0.6.1 (including)
ProsodyProsody0.6.2 (including)0.6.2 (including)
ProsodyProsody0.7.0 (including)0.7.0 (including)
ProsodyProsody0.8.0 (including)0.8.0 (including)
ProsodyProsody0.8.1 (including)0.8.1 (including)
ProsodyProsody0.8.2 (including)0.8.2 (including)
ProsodyProsody0.9.0 (including)0.9.0 (including)
ProsodyProsody0.9.1 (including)0.9.1 (including)
ProsodyProsody0.9.2 (including)0.9.2 (including)
ProsodyUbuntulucid*
ProsodyUbuntuprecise*
ProsodyUbuntuquantal*
ProsodyUbuntusaucy*
ProsodyUbuntutrusty*
ProsodyUbuntuupstream*

References