First published: Tue Jun 21 2011(Updated: )
DJabberd 0.84 and earlier does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jabberd | <=0.84 | |
Jabberd | =0.80 | |
Jabberd | =0.81 | |
Jabberd | =0.82 | |
Jabberd | =0.83 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-1757 is classified as a denial of service vulnerability affecting DJabberd 0.84 and earlier.
To fix CVE-2011-1757, update your DJabberd installation to version 0.85 or later where the recursion detection is improved.
CVE-2011-1757 affects DJabberd versions 0.84 and earlier.
CVE-2011-1757 can be exploited through crafted XML documents containing a large number of nested entity references.
CVE-2011-1757 can result in significant memory and CPU consumption, leading to potential denial-of-service conditions.