PT-2008-3269 · Ignite Realtime · Openfire

Robert Buchholz

·

Publicado

2008-04-11

·

Atualizado

2022-05-01

·

CVE-2008-1728

CVSS v2.0

4.0

Média

VetorAV:N/AC:L/Au:S/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Openfire version 3.4.5
Description The issue allows remote authenticated users to cause a denial of service, resulting in a daemon outage. This is achieved by triggering large outgoing queues without reading messages, specifically in the ConnectionManagerImpl.java component.
Recommendations For Openfire version 3.4.5, consider restricting access to the ConnectionManagerImpl.java component to minimize the risk of exploitation until a patch is available. As a temporary workaround, monitor and limit the size of outgoing queues to prevent daemon outages.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-1728
GHSA-X337-43MR-GG3H

Produtos afetados

Openfire