First published: Tue Mar 21 2006(Updated: )
The SASL negotiation in Jabber Studio jabberd before 2.0s11 allows remote attackers to cause a denial of service ("c2s segfault") by sending a "response stanza before an auth stanza".
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jabberd | =2.0_rc2 | |
Jabberd | =2.0_s7 | |
Jabberd | =2.0_s3 | |
Jabberd | =2.0_a6 | |
Jabberd | =2.0_s4 | |
Jabberd | =2.0_a5 | |
Jabberd | =2.0_s6 | |
Jabberd | =2.0_s8 | |
Jabberd | <=2.0_s10 | |
Jabberd | =2.0_b1 | |
Jabberd | =2.0_a1 | |
Jabberd | =2.0_rc1 | |
Jabberd | =2.0_a3 | |
Jabberd | =2.0_a4 | |
Jabberd | =2.0_s5 | |
Jabberd | =2.0_s1 | |
Jabberd | =2.0_b3 | |
Jabberd | =2.0_s9 | |
Jabberd | =2.0_s2 | |
Jabberd | =2.0_a2 | |
Jabberd | =2.0_b2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-1329 is considered a moderate severity vulnerability as it can lead to a denial of service.
To fix CVE-2006-1329, upgrade Jabberd to versions later than 2.0_s11.
CVE-2006-1329 affects Jabberd versions up to 2.0_s10.
CVE-2006-1329 exposes the application to remote denial of service attacks.
Yes, CVE-2006-1329 can be exploited remotely by sending specially crafted SASL negotiation messages.