Openfire XMPP Server XMPP-Layer Compression Denial of Service Vulnerability
BID:66974
Info
Openfire XMPP Server XMPP-Layer Compression Denial of Service Vulnerability
| Bugtraq ID: | 66974 |
| Class: | Design Error |
| CVE: |
CVE-2014-0360 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 16 2014 12:00AM |
| Updated: | Apr 16 2014 12:00AM |
| Credit: | Giancarlo Pellegrino |
| Vulnerable: |
Igniterealtime Openfire 3.9.1 |
| Not Vulnerable: |
Igniterealtime Openfire 3.9.2 |
Exploit / POC
Openfire XMPP Server XMPP-Layer Compression Denial of Service Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Openfire XMPP Server XMPP-Layer Compression Denial of Service Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Openfire XMPP Server XMPP-Layer Compression Denial of Service Vulnerability
References:
References:
- Uncontrolled Resource Consumption with XMPP-Layer Compression (XMPP Standards Foundation)
- Openfire contains an uncontrolled resource consumption vulnerability (KB CERT)