CVE
- Id
- 49667
- CVE No.
- CVE-2011-1755
- Status
- Candidate
- Description
- jabberd2 before 2.2.14 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
- Phase
- Assigned (20110419)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
539357 | 49667 | CVE-2011-1755 | MLIST:[jabberd2] 20110531 jabberd-2.2.14 release | View |
539358 | 49667 | CVE-2011-1755 | URL:http://www.mail-archive.com/jabberd2@lists.xiaoka.com/msg01655.html | View |
539359 | 49667 | CVE-2011-1755 | CONFIRM:http://codex.xiaoka.com/svn/jabberd2/tags/jabberd-2.2.14/ChangeLog | View |
539360 | 49667 | CVE-2011-1755 | CONFIRM:https://bugzilla.redhat.com/show_bug.cgi?id=700390 | View |
539361 | 49667 | CVE-2011-1755 | CONFIRM:http://support.apple.com/kb/HT5002 | View |
539362 | 49667 | CVE-2011-1755 | APPLE:APPLE-SA-2011-10-12-3 | View |
539363 | 49667 | CVE-2011-1755 | URL:http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html | View |
539364 | 49667 | CVE-2011-1755 | FEDORA:FEDORA-2011-7801 | View |
539365 | 49667 | CVE-2011-1755 | URL:http://lists.fedoraproject.org/pipermail/package-announce/2011-June/061341.html | View |
539366 | 49667 | CVE-2011-1755 | FEDORA:FEDORA-2011-7805 | View |
539367 | 49667 | CVE-2011-1755 | URL:http://lists.fedoraproject.org/pipermail/package-announce/2011-June/061458.html | View |
539368 | 49667 | CVE-2011-1755 | FEDORA:FEDORA-2011-7818 | View |
539369 | 49667 | CVE-2011-1755 | URL:http://lists.fedoraproject.org/pipermail/package-announce/2011-June/061482.html | View |
539370 | 49667 | CVE-2011-1755 | REDHAT:RHSA-2011:0881 | View |
539371 | 49667 | CVE-2011-1755 | URL:http://www.redhat.com/support/errata/RHSA-2011-0881.html | View |
539372 | 49667 | CVE-2011-1755 | REDHAT:RHSA-2011:0882 | View |
539373 | 49667 | CVE-2011-1755 | URL:http://www.redhat.com/support/errata/RHSA-2011-0882.html | View |
539374 | 49667 | CVE-2011-1755 | SUSE:SUSE-SU-2011:0741 | View |
539375 | 49667 | CVE-2011-1755 | URL:https://hermes.opensuse.org/messages/9197650 | View |
539376 | 49667 | CVE-2011-1755 | BID:48250 | View |
539377 | 49667 | CVE-2011-1755 | URL:http://www.securityfocus.com/bid/48250 | View |
539378 | 49667 | CVE-2011-1755 | SECUNIA:44787 | View |
539379 | 49667 | CVE-2011-1755 | URL:http://secunia.com/advisories/44787 | View |
539380 | 49667 | CVE-2011-1755 | SECUNIA:45112 | View |
539381 | 49667 | CVE-2011-1755 | URL:http://secunia.com/advisories/45112 | View |
539382 | 49667 | CVE-2011-1755 | SECUNIA:44957 | View |
539383 | 49667 | CVE-2011-1755 | URL:http://secunia.com/advisories/44957 | View |
539384 | 49667 | CVE-2011-1755 | XF:jabberd-xml-entity-dos(67770) | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
34303 | JVNDB-2011-004545 | OProfile の utils/opcontrol における権限を取得される脆弱性 | OProfile の utils/opcontrol には、eval インジェクション攻撃を実行される、および権限を取得される脆弱性が存在します。 | CVE-2011-1760 | 49667 | 7.2 | http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-004545.html | View |