ejabberd 'client2server' Message Remote Denial of Service Vulnerability
BID:38003
Info
ejabberd 'client2server' Message Remote Denial of Service Vulnerability
| Bugtraq ID: | 38003 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2010-0305 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 29 2010 12:00AM |
| Updated: | Apr 13 2015 09:23PM |
| Credit: | Reported by the vendor |
| Vulnerable: |
Gentoo Linux ejabberd ejabberd 2.1.2 Debian Linux 5.0 sparc Debian Linux 5.0 s/390 Debian Linux 5.0 powerpc Debian Linux 5.0 mipsel Debian Linux 5.0 mips Debian Linux 5.0 m68k Debian Linux 5.0 ia-64 Debian Linux 5.0 ia-32 Debian Linux 5.0 hppa Debian Linux 5.0 armel Debian Linux 5.0 arm Debian Linux 5.0 amd64 Debian Linux 5.0 alpha Debian Linux 5.0 |
| Not Vulnerable: |
ejabberd ejabberd 2.1.3 |
Discussion
ejabberd 'client2server' Message Remote Denial of Service Vulnerability
The 'ejabberd' application is prone to a denial-of-service vulnerability.
An attacker can exploit this issue to crash the affected application, denying service to legitimate users.
Versions prior to ejabberd 2.1.3 are vulnerable; other versions may also be affected.
The 'ejabberd' application is prone to a denial-of-service vulnerability.
An attacker can exploit this issue to crash the affected application, denying service to legitimate users.
Versions prior to ejabberd 2.1.3 are vulnerable; other versions may also be affected.
Exploit / POC
ejabberd 'client2server' Message Remote Denial of Service Vulnerability
Attackers can use readily available network utilities to exploit this issue.
Attackers can use readily available network utilities to exploit this issue.
Solution / Fix
ejabberd 'client2server' Message Remote Denial of Service Vulnerability
Solution:
Updates are available. Please see the references for more information.
Debian Linux 5.0 ia-64
Debian Linux 5.0 arm
Debian Linux 5.0 armel
Debian Linux 5.0 amd64
Debian Linux 5.0 alpha
Debian Linux 5.0 ia-32
Debian Linux 5.0 s/390
Debian Linux 5.0 mipsel
Debian Linux 5.0 powerpc
Debian Linux 5.0 sparc
Solution:
Updates are available. Please see the references for more information.
Debian Linux 5.0 ia-64
-
Debian ejabberd_2.0.1-6+lenny2_ia64.deb
http://security.debian.org/pool/updates/main/e/ejabberd/ejabberd_2.0.1 -6+lenny2_ia64.deb
Debian Linux 5.0 arm
-
Debian ejabberd_2.0.1-6+lenny2_arm.deb
http://security.debian.org/pool/updates/main/e/ejabberd/ejabberd_2.0.1 -6+lenny2_arm.deb
Debian Linux 5.0 armel
-
Debian ejabberd_2.0.1-6+lenny2_armel.deb
http://security.debian.org/pool/updates/main/e/ejabberd/ejabberd_2.0.1 -6+lenny2_armel.deb
Debian Linux 5.0 amd64
-
Debian ejabberd_2.0.1-6+lenny2_amd64.deb
http://security.debian.org/pool/updates/main/e/ejabberd/ejabberd_2.0.1 -6+lenny2_amd64.deb
Debian Linux 5.0 alpha
-
Debian ejabberd_2.0.1-6+lenny2_alpha.deb
http://security.debian.org/pool/updates/main/e/ejabberd/ejabberd_2.0.1 -6+lenny2_alpha.deb
Debian Linux 5.0 ia-32
-
Debian ejabberd_2.0.1-6+lenny2_i386.deb
http://security.debian.org/pool/updates/main/e/ejabberd/ejabberd_2.0.1 -6+lenny2_i386.deb
Debian Linux 5.0 s/390
-
Debian ejabberd_2.0.1-6+lenny2_s390.deb
http://security.debian.org/pool/updates/main/e/ejabberd/ejabberd_2.0.1 -6+lenny2_s390.deb
Debian Linux 5.0 mipsel
-
Debian ejabberd_2.0.1-6+lenny2_mipsel.deb
http://security.debian.org/pool/updates/main/e/ejabberd/ejabberd_2.0.1 -6+lenny2_mipsel.deb
Debian Linux 5.0 powerpc
-
Debian ejabberd_2.0.1-6+lenny2_powerpc.deb
http://security.debian.org/pool/updates/main/e/ejabberd/ejabberd_2.0.1 -6+lenny2_powerpc.deb
Debian Linux 5.0 sparc
-
Debian ejabberd_2.0.1-6+lenny2_sparc.deb
http://security.debian.org/pool/updates/main/e/ejabberd/ejabberd_2.0.1 -6+lenny2_sparc.deb
References
ejabberd 'client2server' Message Remote Denial of Service Vulnerability
References:
References:
- ejabberd crashes when c2s message queue gets overloaded (ejabberd)
- Vendor Homepage (ejabberd)