First published: Wed Jun 22 2011(Updated: )
XMLParser.pm in DJabberd before 0.85 allows remote authenticated users to read arbitrary files, and possibly send HTTP requests to intranet servers or cause a denial of service (CPU and memory consumption), via an XML external entity declaration in conjunction with an entity reference, a different vulnerability than CVE-2011-1757.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jabberd | <=0.84 | |
Jabberd | =0.80 | |
Jabberd | =0.81 | |
Jabberd | =0.82 | |
Jabberd | =0.83 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-2206 is classified as a moderate severity vulnerability as it allows authenticated users to read arbitrary files and potentially disrupt services.
To fix CVE-2011-2206, upgrade DJabberd to version 0.85 or later, which contains patches to mitigate the vulnerability.
CVE-2011-2206 affects all versions of DJabberd prior to version 0.85, including versions 0.80 to 0.84.
CVE-2011-2206 can enable remote authenticated users to read arbitrary files, send unauthorized HTTP requests, and potentially cause denial of service.
Yes, CVE-2011-2206 is exploitable remotely by authenticated users through XML external entity declarations.