Jabber Studio JabberD Remote Denial Of Service Vulnerability
BID:11231
Info
Jabber Studio JabberD Remote Denial Of Service Vulnerability
| Bugtraq ID: | 11231 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 21 2004 12:00AM |
| Updated: | Sep 21 2004 12:00AM |
| Credit: | Discovery of this issue is credited to Jose Antonio Calvo. |
| Vulnerable: |
JabberStudio jadc2s 0.9 JabberStudio jadc2s 0.8 JabberStudio jadc2s 0.7 JabberStudio jadc2s 0.6 JabberStudio jabberd 1.4.3 JabberStudio jabberd 1.4.2 a JabberStudio jabberd 1.4.2 JabberStudio jabberd 1.4.1 JabberStudio jabberd 1.4 |
| Not Vulnerable: | |
Discussion
Jabber Studio JabberD Remote Denial Of Service Vulnerability
Jabber Studio jabberd is reportedly affected by a remote denial of service vulnerability. This issue is due to a failure of the application to properly handle malformed network messages.
An attacker may leverage this issue by causing the affected server to crash, denying service to legitimate users.
Jabber Studio jabberd is reportedly affected by a remote denial of service vulnerability. This issue is due to a failure of the application to properly handle malformed network messages.
An attacker may leverage this issue by causing the affected server to crash, denying service to legitimate users.
Exploit / POC
Jabber Studio JabberD Remote Denial Of Service Vulnerability
No exploit is required to leverage this issue.
No exploit is required to leverage this issue.
Solution / Fix
Jabber Studio JabberD Remote Denial Of Service Vulnerability
Solution:
It has been reported that this issue has been resolved in the CVS version of the software, although this has not been confirmed.
Gentoo Linux has released an advisory (GLSA 200409-31). Gentoo has advised that all jabberd users should upgrade to the latest version:
# emerge sync
# emerge -pv ">=net-im/jabberd-1.4.3-r4"
# emerge ">=net-im/jabberd-1.4.3-r4"
For more information please see the referenced Gentoo advisory.
Solution:
It has been reported that this issue has been resolved in the CVS version of the software, although this has not been confirmed.
Gentoo Linux has released an advisory (GLSA 200409-31). Gentoo has advised that all jabberd users should upgrade to the latest version:
# emerge sync
# emerge -pv ">=net-im/jabberd-1.4.3-r4"
# emerge ">=net-im/jabberd-1.4.3-r4"
For more information please see the referenced Gentoo advisory.
References
Jabber Studio JabberD Remote Denial Of Service Vulnerability
References:
References:
- jabberd Project Page (JabberStudio)
- jadc2s Project Page (JabberStudio)
- Possible DoS attack against jabberd 1.4.3 and jadc2s 0.9.0 (Matthias Wimmer
)