PT-2004-2295 · Jadc2S+2 · Jadc2S+2
Published
2004-09-21
·
Updated
2017-07-11
·
CVE-2004-1378
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions:
jabberd versions 1.4.3 and earlier
jadc2s versions 0.9.0 and earlier
Description:
The issue allows remote attackers to cause a denial of service, resulting in an application crash, by sending a malformed packet to a socket that accepts XML connections. This is due to a problem in the expat XML parser code.
Recommendations:
For jabberd versions 1.4.3 and earlier, consider updating to a version that fixes the issue in the expat XML parser code.
For jadc2s versions 0.9.0 and earlier, consider updating to a version that fixes the issue in the expat XML parser code.
As a temporary workaround, consider restricting XML connections to trusted sources to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Expat Xml Parser
Jabberd
Jadc2S