Jabber Studio JabberD Remote Denial Of Service Vulnerability
BID:17155
Info
Jabber Studio JabberD Remote Denial Of Service Vulnerability
| Bugtraq ID: | 17155 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2006-1329 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 20 2006 12:00AM |
| Updated: | Apr 02 2010 01:02AM |
| Credit: | The vendor credits Jeremy Lunn and Stepehn Marquard with the discovery of this issue. |
| Vulnerable: |
Redhat Network Satellite (for RHEL 4) 4.2 Redhat Network Satellite (for RHEL 3) 4.2 Redhat Network Proxy (for RHEL 4) 5.0 Redhat Network Proxy (for RHEL 4) 4.2 Redhat Network Proxy (for RHEL 3) 4.2 Jabber Software Foundation Jabber Server 2.0 s9 Jabber Software Foundation Jabber Server 2.0 s8 Jabber Software Foundation Jabber Server 2.0 s10 Jabber Software Foundation Jabber Server 2.0 Apple Mac OS X Server 10.6.2 Apple Mac OS X Server 10.6.1 Apple Mac OS X Server 10.5.8 Apple Mac OS X Server 10.6 |
| Not Vulnerable: |
Jabber Software Foundation Jabber Server 2.0 s11 Apple Mac OS X Server 10.6.3 |
Discussion
Jabber Studio JabberD Remote Denial Of Service Vulnerability
Jabber Studio 'jabberd' is affected by a remote denial-of-service vulnerability. This issue is due to the application's failure to properly handle malformed network messages.
An attacker may leverage this issue by causing the affected server to crash, denying service to legitimate users.
Jabber Studio 'jabberd' is affected by a remote denial-of-service vulnerability. This issue is due to the application's failure to properly handle malformed network messages.
An attacker may leverage this issue by causing the affected server to crash, denying service to legitimate users.
Exploit / POC
Jabber Studio JabberD Remote Denial Of Service Vulnerability
This issue can be exploited through the use of a client application for jabber.
This issue can be exploited through the use of a client application for jabber.
Solution / Fix
Jabber Studio JabberD Remote Denial Of Service Vulnerability
Solution:
The vendor has released Jabber Server 2.0s11 to address this issue. Please see the referenced vendor advisory for information on obtaining and applying the appropriate updates.
Apple Mac OS X Server 10.6
Apple Mac OS X Server 10.5.8
Apple Mac OS X Server 10.6.1
Apple Mac OS X Server 10.6.2
Jabber Software Foundation Jabber Server 2.0
Jabber Software Foundation Jabber Server 2.0 s8
Jabber Software Foundation Jabber Server 2.0 s9
Jabber Software Foundation Jabber Server 2.0 s10
Solution:
The vendor has released Jabber Server 2.0s11 to address this issue. Please see the referenced vendor advisory for information on obtaining and applying the appropriate updates.
Apple Mac OS X Server 10.6
-
Apple MacOSXServerUpdCombo10.6.3.dmg
http://www.apple.com/support/downloads/
Apple Mac OS X Server 10.5.8
-
Apple SecUpdSrvr2010-002Leo.dmg
http://www.apple.com/support/downloads/
Apple Mac OS X Server 10.6.1
-
Apple MacOSXServerUpdCombo10.6.3.dmg
http://www.apple.com/support/downloads/
Apple Mac OS X Server 10.6.2
-
Apple MacOSXServerUpd10.6.3.dmg
http://www.apple.com/support/downloads/
Jabber Software Foundation Jabber Server 2.0
-
Jabber Software Foundation jabberd-2.0s11.tar.gz
http://jabberstudio.org/projects/jabberd2/releases/download.php?file=j abberd-2.0s11.tar.gz
Jabber Software Foundation Jabber Server 2.0 s8
-
Jabber Software Foundation jabberd-2.0s11.tar.gz
http://jabberstudio.org/projects/jabberd2/releases/download.php?file=j abberd-2.0s11.tar.gz
Jabber Software Foundation Jabber Server 2.0 s9
-
Jabber Software Foundation jabberd-2.0s11.tar.gz
http://jabberstudio.org/projects/jabberd2/releases/download.php?file=j abberd-2.0s11.tar.gz
Jabber Software Foundation Jabber Server 2.0 s10
-
Jabber Software Foundation jabberd-2.0s11.tar.gz
http://jabberstudio.org/projects/jabberd2/releases/download.php?file=j abberd-2.0s11.tar.gz
References
Jabber Studio JabberD Remote Denial Of Service Vulnerability
References:
References:
- jabberd Project Page (JabberStudio)
- jabberd2s11 - stable release 11 (security release) (Justin Kirby)
- RHSA-2008:0263-2 Red Hat Network Proxy Server security update (Red Hat)
- RHSA-2008:0523-1 Low: Red Hat Network Proxy Server security update (Red Hat)
- RHSA-2008:0524-4 Low: Red Hat Network Satellite Server security update (Red Hat)