Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8jhg-7mm6-vg49

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Prosody before 0.9.4 does not properly restrict the processing of compressed XML elements, which allows remote attackers to cause a denial of service (resource consumption) via a crafted XMPP stream, aka an "xmppbomb" attack, related to core/portmanager.lua and util/xmppstream.lua.

Prosody before 0.9.4 does not properly restrict the processing of compressed XML elements, which allows remote attackers to cause a denial of service (resource consumption) via a crafted XMPP stream, aka an "xmppbomb" attack, related to core/portmanager.lua and util/xmppstream.lua.

EPSS

Процентиль: 84%
0.02179
Низкий

Связанные уязвимости

ubuntu
почти 12 лет назад

Prosody before 0.9.4 does not properly restrict the processing of compressed XML elements, which allows remote attackers to cause a denial of service (resource consumption) via a crafted XMPP stream, aka an "xmppbomb" attack, related to core/portmanager.lua and util/xmppstream.lua.

nvd
почти 12 лет назад

Prosody before 0.9.4 does not properly restrict the processing of compressed XML elements, which allows remote attackers to cause a denial of service (resource consumption) via a crafted XMPP stream, aka an "xmppbomb" attack, related to core/portmanager.lua and util/xmppstream.lua.

debian
почти 12 лет назад

Prosody before 0.9.4 does not properly restrict the processing of comp ...

EPSS

Процентиль: 84%
0.02179
Низкий