CVE-2014-2743: High severity Lightwitch Metronome vulnerability
plugins/modcompression.lua in Lightwitch Metronome through 3.4 does not properly restrict the processing of compressed XML elements, which allows remote attackers to cause a denial of service (resource consumption) via a crafted XMPP stream, aka an "xmppbomb" attack.
Affected Software
Event History
Frequently Asked Questions
What is the CVE-2014-2743 vulnerability?
CVE-2014-2743 is a vulnerability in Lightwitch Metronome that allows remote attackers to consume resources and cause denial of service through crafted XMPP streams.
What is the severity of CVE-2014-2743?
CVE-2014-2743 has a medium severity rating due to its potential for denial of service attacks.
How do I fix CVE-2014-2743?
To fix CVE-2014-2743, upgrade Lightwitch Metronome to a version later than 3.4 where the vulnerability is addressed.
Which versions of Lightwitch Metronome are affected by CVE-2014-2743?
CVE-2014-2743 affects all versions of Lightwitch Metronome up to and including version 3.4.
What kind of attack does CVE-2014-2743 enable?
CVE-2014-2743 enables an "xmppbomb" attack, which can cause denial of service through excessive resource consumption.