PT-2008-3269 · Ignite Realtime · Openfire
Robert Buchholz
·
Published
2008-04-11
·
Updated
2022-05-01
·
CVE-2008-1728
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Openfire version 3.4.5
Description
The issue allows remote authenticated users to cause a denial of service, resulting in a daemon outage. This is achieved by triggering large outgoing queues without reading messages, specifically in the ConnectionManagerImpl.java component.
Recommendations
For Openfire version 3.4.5, consider restricting access to the ConnectionManagerImpl.java component to minimize the risk of exploitation until a patch is available. As a temporary workaround, monitor and limit the size of outgoing queues to prevent daemon outages.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openfire