CVE-2011-1754
21.06.2011, 02:52
jabberd14 1.6.1.1 and earlier does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.Enginsight
Vendor | Product | Version |
---|---|---|
jabberd | jabberd14 | 𝑥 ≤ 1.6.1.1 |
jabberd | jabberd14 | 1.4.1 |
jabberd | jabberd14 | 1.4.2 |
jabberd | jabberd14 | 1.4.3 |
jabberd | jabberd14 | 1.4.3.1 |
jabberd | jabberd14 | 1.4.4 |
jabberd | jabberd14 | 1.6.0 |
jabberd | jabberd14 | 1.6.1 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
References