CVE-2015-2058: Infoleak
Published Aug 12, 2015
·Updated
c2s/c2s.c in Jabber Open Source Server 2.3.2 and earlier truncates data without ensuring it remains valid UTF-8, which allows remote authenticated users to read system memory or possibly have other unspecified impact via a crafted JID.
Affected Software
1 affected component
jabberd2 jabberd2<=2.3.2
Event History
Aug 12, 2015
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-2058?
CVE-2015-2058 has a severity rating of moderate due to potential unauthorized access to system memory.
2
How do I fix CVE-2015-2058?
To fix CVE-2015-2058, upgrade to Jabber Open Source Server version 2.3.3 or later.
3
Who is affected by CVE-2015-2058?
CVE-2015-2058 affects users of Jabber Open Source Server version 2.3.2 and earlier.
4
What types of vulnerabilities does CVE-2015-2058 represent?
CVE-2015-2058 represents a data truncation vulnerability that may lead to memory exposure.
5
What can exploit CVE-2015-2058?
Remote authenticated users can exploit CVE-2015-2058 by sending a crafted JID that truncates data incorrectly.