Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2011-1755

Опубликовано: 31 мая 2011
Источник: redhat
CVSS2: 5
EPSS Низкий

Описание

jabberd2 before 2.2.14 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.

Отчет

Vulnerable. This issue has been addressed in Red Hat Network Satellite Server v 5.4.1 via RHSA-2011:0882 https://rhn.redhat.com/errata/RHSA-2011-0882.html and in Red Hat Network Proxy Server v5.4.1 via RHSA-2011:0881 https://rhn.redhat.com/errata/RHSA-2011-0881.html. This issue is not planned to be fixed in Red Hat Network Satellite Server versions 5.0.2, 5.1.1, 5.2.1, 5.3.0 and not planned to be fixed in Red Hat Network Proxy Server versions 5.0.2, 5.1.1, 5.2.1, and 5.3.0.

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=700390jabberd: DoS via the XML "billion laughs attack"

EPSS

Процентиль: 92%
0.08459
Низкий

5 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 14 лет назад

jabberd2 before 2.2.14 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.

CVSS3: 7.5
nvd
больше 14 лет назад

jabberd2 before 2.2.14 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.

CVSS3: 7.5
debian
больше 14 лет назад

jabberd2 before 2.2.14 does not properly detect recursion during entit ...

CVSS3: 7.5
github
больше 3 лет назад

jabberd2 before 2.2.14 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.

EPSS

Процентиль: 92%
0.08459
Низкий

5 Medium

CVSS2