OSVDB ID: 10257

Title: Multiple Jabber Client Malformed Byte Sequence DoS

Info

Disclosure

Sep 19, 2004

Discovery

Unknown

Dates

Exploit

Sep 19, 2004

Solution

Unknown

Description

jabberd and jadc2s contains a flaw that may allow a remote denial of service. The issue is triggered due to the parsing of XML messages. By sending a malformed byte sequence of 0xEF, 0xBB, 0xBF to certain sockets, a remote attacker could cause the application to crash, resulting in a loss of availability.

Classification

Location: Remote / Network Access
Attack Type: Denial of Service
Impact: Loss of Availability
Exploit: Exploit Public
Disclosure: OSVDB Verified, Vendor Verified

Solution

Contact your vendor for an appropriate upgrade. An upgrade is required as there are no known workarounds.

Products

Rob Norris

jabberd

1.4.3

jadc2s

0.9.0

References

Credit

  • José Antonio Calvo - joshescomposlinux.org -


Direct URL: http://osvdb.org/10257