CVE-2014-2744: Input Validation
plugins/modcompression.lua in (1) Prosody before 0.9.4 and (2) Lightwitch Metronome through 3.4 negotiates stream compression while a session is unauthenticated, which allows remote attackers to cause a denial of service (resource consumption) via compressed XML elements in an XMPP stream, aka an "xmppbomb" attack.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2744?
CVE-2014-2744 has been classified as a denial of service vulnerability.
How do I fix CVE-2014-2744?
To mitigate CVE-2014-2744, upgrade to Prosody version 0.9.4 or later, or to Lightwitch Metronome version 3.5 or later.
What causes the vulnerability in CVE-2014-2744?
CVE-2014-2744 is caused by stream compression negotiation during unauthenticated sessions, allowing attackers to exploit resource consumption.
Which versions are affected by CVE-2014-2744?
CVE-2014-2744 affects Prosody versions before 0.9.4 and Lightwitch Metronome versions up to 3.4.
What type of systems are impacted by CVE-2014-2744?
CVE-2014-2744 impacts XMPP based systems that utilize Prosody or Lightwitch Metronome for communication.