First published: Tue Apr 16 2013(Updated: )
The XML parser in the server in Cisco Unified Presence (CUP) allows remote authenticated users to cause a denial of service (jabberd daemon crash) via crafted XML content in an XMPP message, aka Bug ID CSCue13912.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unified Presence |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-1197 has a medium severity rating due to its potential to cause a denial of service.
To resolve CVE-2013-1197, ensure that you apply the latest patches provided by Cisco for the Unified Presence software.
CVE-2013-1197 affects remote authenticated users of Cisco Unified Presence.
CVE-2013-1197 is a denial of service vulnerability originating from an XML parsing issue in Cisco Unified Presence.
An attacker can crash the jabberd daemon by sending crafted XML content in an XMPP message.