First published: Fri Apr 11 2008(Updated: )
ConnectionManagerImpl.java in Ignite Realtime Openfire 3.4.5 allows remote authenticated users to cause a denial of service (daemon outage) by triggering large outgoing queues without reading messages.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
maven/org.igniterealtime.openfire:openfire | <3.5.0 | 3.5.0 |
maven/org.igniterealtime.openfire:parent | <3.5.0 | 3.5.0 |
Openfire | =3.4.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-1728 has a severity rating of medium as it allows denial of service through large outgoing message queues.
To fix CVE-2008-1728, upgrade to Ignite Realtime Openfire version 3.5.0 or later.
CVE-2008-1728 affects Ignite Realtime Openfire version 3.4.5.
CVE-2008-1728 is classified as a denial of service vulnerability.
CVE-2008-1728 can be exploited by remote authenticated users.