CVE Vulnerabilities

CVE-2014-2745

Published: Apr 11, 2014 | Modified: Apr 19, 2014
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.8 HIGH
AV:N/AC:L/Au:N/C:N/I:N/A:C
RedHat/V2
RedHat/V3
Ubuntu

Prosody before 0.9.4 does not properly restrict the processing of compressed XML elements, which allows remote attackers to cause a denial of service (resource consumption) via a crafted XMPP stream, aka an xmppbomb attack, related to core/portmanager.lua and util/xmppstream.lua.

Affected Software

Name Vendor Start Version End Version
Prosody Prosody * 0.9.3 (including)
Prosody Prosody 0.1.0 (including) 0.1.0 (including)
Prosody Prosody 0.2.0 (including) 0.2.0 (including)
Prosody Prosody 0.3.0 (including) 0.3.0 (including)
Prosody Prosody 0.4.0 (including) 0.4.0 (including)
Prosody Prosody 0.4.1 (including) 0.4.1 (including)
Prosody Prosody 0.4.2 (including) 0.4.2 (including)
Prosody Prosody 0.5.0 (including) 0.5.0 (including)
Prosody Prosody 0.5.1 (including) 0.5.1 (including)
Prosody Prosody 0.5.2 (including) 0.5.2 (including)
Prosody Prosody 0.6.0 (including) 0.6.0 (including)
Prosody Prosody 0.6.1 (including) 0.6.1 (including)
Prosody Prosody 0.6.2 (including) 0.6.2 (including)
Prosody Prosody 0.7.0 (including) 0.7.0 (including)
Prosody Prosody 0.8.0 (including) 0.8.0 (including)
Prosody Prosody 0.8.1 (including) 0.8.1 (including)
Prosody Prosody 0.8.2 (including) 0.8.2 (including)
Prosody Prosody 0.9.0 (including) 0.9.0 (including)
Prosody Prosody 0.9.1 (including) 0.9.1 (including)
Prosody Prosody 0.9.2 (including) 0.9.2 (including)

References