M-Link XMPP Server XMPP-Layer Compression Denial of Service Vulnerability
BID:66730
Info
M-Link XMPP Server XMPP-Layer Compression Denial of Service Vulnerability
| Bugtraq ID: | 66730 |
| Class: | Design Error |
| CVE: |
CVE-2014-2742 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 07 2014 12:00AM |
| Updated: | Apr 07 2014 12:00AM |
| Credit: | Giancarlo Pellegrino |
| Vulnerable: |
Isode M-Link 16.0 |
| Not Vulnerable: |
Isode M-Link 16.0v7 |
Exploit / POC
M-Link XMPP Server XMPP-Layer Compression Denial of Service Vulnerability
Attackers can exploit this issue using readily available tools.
Attackers can exploit this issue using readily available tools.
Solution / Fix
M-Link XMPP Server XMPP-Layer Compression Denial of Service Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
M-Link XMPP Server XMPP-Layer Compression Denial of Service Vulnerability
References:
References:
- (Openfire M-Link Metronome Prosody Tigase) Possible CVE Request: Uncontrolled Re (seclists.org)
- Isode Product Page (Isode)
- Uncontrolled Resource Consumption with XMPP-Layer Compression (XMPP Standards Foundation)