From a24567fbc43f221b14e805f9bc0b7c6d16911c46 Mon Sep 17 00:00:00 2001 From: Alex Legler Date: Sun, 8 Mar 2015 22:02:38 +0100 Subject: Import existing advisories --- glsa-200409-31.xml | 72 ++++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 72 insertions(+) create mode 100644 glsa-200409-31.xml (limited to 'glsa-200409-31.xml') diff --git a/glsa-200409-31.xml b/glsa-200409-31.xml new file mode 100644 index 00000000..f0ff35b6 --- /dev/null +++ b/glsa-200409-31.xml @@ -0,0 +1,72 @@ + + + + + + + jabberd 1.x: Denial of Service vulnerability + + The jabberd server was found to be vulnerable to a remote Denial of Service + attack. + + jabberd + September 23, 2004 + May 22, 2006: 02 + 64741 + remote + + + 1.4.3-r4 + 1.4.3-r3 + + + +

+ Jabber is a set of streaming XML protocols enabling message, presence, + and other structured information exchange between two hosts. jabberd is + the original implementation of the Jabber protocol server. +

+
+ +

+ Jose Antonio Calvo found a defect in routines handling XML parsing of + incoming data. jabberd 1.x may crash upon reception of invalid data on + any socket connection on which XML is parsed. +

+
+ +

+ A remote attacker may send a specific sequence of bytes to an open + socket to crash the jabberd server, resulting in a Denial of Service. +

+
+ +

+ There is no known workaround at this time. +

+
+ +

+ All jabberd users should upgrade to the latest version: +

+ + # emerge sync + + # emerge -pv ">=net-im/jabberd-1.4.3-r4" + # emerge ">=net-im/jabberd-1.4.3-r4" +
+ + Vulnerability disclosure + Jabber announcement + CVE-2004-1378 + + + koon + + + koon + + + koon + +
-- cgit v1.2.3-65-gdbad