[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248364

 
 

909

 
 

195388

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-2250-1 citadel -- denial of service

ID: oval:org.secpod.oval:def:600536Date: (C)2011-06-01   (M)2022-10-10
Class: PATCHFamily: unix




Wouter Coekaerts discovered that the jabber server component of citadel, a complete and feature-rich groupware server, is vulnerable to the so-called "billion laughs" attack because it does not prevent entity expansion on received data. This allows an attacker to perform denial of service attacks against the service by sending specially crafted XML data to it.

Platform:
Debian 5.0
Debian 6.0
Product:
citadel-client
Reference:
DSA-2250-1
CVE-2011-1756
CVE    1
CVE-2011-1756
CPE    3
cpe:/a:citadel:citadel-client
cpe:/o:debian:debian_linux:5.0
cpe:/o:debian:debian_linux:6.0

© SecPod Technologies