Oval Definition:oval:org.mitre.oval:def:12641
Revision Date:2014-07-21Version:20
Title:DSA-2249-1 jabberd14 -- denial of service
Description:Wouter Coekaerts discovered that jabberd14, an instant messaging server using the Jabber/XMPP protocol, is vulnerable to the so-called "billion laughs" attack because it does not prevent entity expansion on received data. This allows an attacker to perform denial of service attacks against the service by sending specially crafted XML data to it. The oldstable distribution, does not contain jabberd14.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2011-1754
DSA-2249-1
Platform(s):Debian GNU/kFreeBSD 6.0
Debian GNU/Linux 6.0
Product(s):jabberd14
Definition Synopsis
  • Debian 6.0 is installed
  • AND GNU/Linux or GNU/kFreeBSD kernel
  • Debian GNU/Linux is installed
  • OR Debian GNU/kFreeBSD is installed
  • AND Installed architecture is all
  • AND jabberd14 DPKG is earlier than 1.6.1.1-5+squeeze1
  • BACK