CVE-2011-1757: Medium severity jabberd vulnerability
DJabberd 0.84 and earlier does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1757?
CVE-2011-1757 is classified as a denial of service vulnerability affecting DJabberd 0.84 and earlier.
How do I fix CVE-2011-1757?
To fix CVE-2011-1757, update your DJabberd installation to version 0.85 or later where the recursion detection is improved.
Which versions of DJabberd are affected by CVE-2011-1757?
CVE-2011-1757 affects DJabberd versions 0.84 and earlier.
What types of attacks can exploit CVE-2011-1757?
CVE-2011-1757 can be exploited through crafted XML documents containing a large number of nested entity references.
What impact does CVE-2011-1757 have on systems?
CVE-2011-1757 can result in significant memory and CPU consumption, leading to potential denial-of-service conditions.