CVE-2013-1197: Input Validation
Published Apr 16, 2013
·Updated
The XML parser in the server in Cisco Unified Presence (CUP) allows remote authenticated users to cause a denial of service (jabberd daemon crash) via crafted XML content in an XMPP message, aka Bug ID CSCue13912.
Affected Software
1 affected component
Cisco Unified Presence
Event History
Apr 16, 2013
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-1197?
CVE-2013-1197 has a medium severity rating due to its potential to cause a denial of service.
2
How do I fix CVE-2013-1197?
To resolve CVE-2013-1197, ensure that you apply the latest patches provided by Cisco for the Unified Presence software.
3
Who is affected by CVE-2013-1197?
CVE-2013-1197 affects remote authenticated users of Cisco Unified Presence.
4
What type of vulnerability is CVE-2013-1197?
CVE-2013-1197 is a denial of service vulnerability originating from an XML parsing issue in Cisco Unified Presence.
5
What can an attacker achieve with CVE-2013-1197?
An attacker can crash the jabberd daemon by sending crafted XML content in an XMPP message.