PT-2008-3269 · Ignite Realtime · Openfire

Robert Buchholz

·

Published

2008-04-11

·

Updated

2022-05-01

·

CVE-2008-1728

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Openfire version 3.4.5
Description The issue allows remote authenticated users to cause a denial of service, resulting in a daemon outage. This is achieved by triggering large outgoing queues without reading messages, specifically in the ConnectionManagerImpl.java component.
Recommendations For Openfire version 3.4.5, consider restricting access to the ConnectionManagerImpl.java component to minimize the risk of exploitation until a patch is available. As a temporary workaround, monitor and limit the size of outgoing queues to prevent daemon outages.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-1728
GHSA-X337-43MR-GG3H

Affected Products

Openfire