|
|
Log in / Subscribe / Register

ejabberd: denial of service

Package(s):ejabberd CVE #(s):CVE-2011-4320
Created:December 19, 2011 Updated:December 21, 2011
Description: From the Red Hat bugzilla:

A denial of service flaw was found in the way PubSub extension of the ejabberd, a distributed, fault-tolerant Jabber/XMPP server, performed processing of certain, malformed <publish/> stanzas. A remote attacker, authenticated Jabber user, could send a specially-crafted request to Jabber server, leading to the jabberd daemon to enter an infinite loop and consume excessive amount of CPU, while processing the stanza.

Alerts:
Gentoo 201206-10 ejabberd 2012-06-21
Fedora FEDORA-2011-16282 ejabberd 2011-11-23
Fedora FEDORA-2011-16281 ejabberd 2011-11-23

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds