ejabberd: denial of service
| Package(s): | ejabberd |
CVE #(s): | CVE-2011-4320
|
| Created: | December 19, 2011 |
Updated: | December 21, 2011 |
| Description: |
From the Red Hat bugzilla:
A denial of service flaw was found in the way PubSub extension of the ejabberd, a distributed, fault-tolerant Jabber/XMPP server, performed processing of certain, malformed <publish/> stanzas. A remote attacker, authenticated Jabber user, could send a specially-crafted request to Jabber server, leading to the jabberd daemon to enter an infinite loop and consume excessive amount of CPU, while processing the stanza. |
| Alerts: |
|