Описание
DJabberd 0.84 and earlier does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
Уязвимые конфигурации
Конфигурация 1Версия до 0.84 (включая)
Одно из
cpe:2.3:a:brad_fitzpatrick:djabberd:*:*:*:*:*:*:*:*
cpe:2.3:a:brad_fitzpatrick:djabberd:0.80:*:*:*:*:*:*:*
cpe:2.3:a:brad_fitzpatrick:djabberd:0.81:*:*:*:*:*:*:*
cpe:2.3:a:brad_fitzpatrick:djabberd:0.82:*:*:*:*:*:*:*
cpe:2.3:a:brad_fitzpatrick:djabberd:0.83:*:*:*:*:*:*:*
EPSS
Процентиль: 64%
0.00474
Низкий
5 Medium
CVSS2
Дефекты
CWE-399
Связанные уязвимости
debian
больше 14 лет назад
DJabberd 0.84 and earlier does not properly detect recursion during en ...
github
больше 3 лет назад
DJabberd 0.84 and earlier does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
EPSS
Процентиль: 64%
0.00474
Низкий
5 Medium
CVSS2
Дефекты
CWE-399