CVE-2011-1755

jabberd2 before 2.2.14 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
XML Entity Expansion
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 91%
VendorProductVersion
jabberd2jabberd2
𝑥
< 2.2.14
applemac_os_x
𝑥
< 10.6.8
applemac_os_x
10.7.0 ≤
𝑥
< 10.7.2
applemac_os_x_server
𝑥
< 10.6.8
applemac_os_x_server
10.7.0 ≤
𝑥
< 10.7.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
jabberd2
bullseye
2.7.0-2
fixed
bookworm
2.7.0-4
fixed
sid
2.7.0-7
fixed
trixie
2.7.0-7
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
jabberd2
natty
Fixed 2.2.8-2ubuntu4.1
released
maverick
Fixed 2.2.8-2ubuntu4.0.10.10.1
released
lucid
Fixed 2.2.8-2ubuntu4.0.10.04.1
released
hardy
Fixed 2.0s11-1ubuntu4.1
released
dapper
ignored
References