CVE-2011-1755
published 2011-06-21CVE-2011-1755: jabberd2 before 2.2.14 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU…
PriorityP335high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
3.66%
88.5th percentile
jabberd2 before 2.2.14 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | < 10.6.8 | 10.6.8 |
| apple | mac_os_x | >= 10.7.0 < 10.7.2 | 10.7.2 |
| apple | mac_os_x_server | < 10.6.8 | 10.6.8 |
| apple | mac_os_x_server | >= 10.7.0 < 10.7.2 | 10.7.2 |
| debian | jabberd2 | < jabberd2 2.2.8-2.1 (bookworm) | jabberd2 2.2.8-2.1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| jabberd2 | jabberd2 | < 2.2.14 | 2.2.14 |
| jabberd2 | jabberd2 | >= 0 < 2.2.8-2.1 | 2.2.8-2.1 |
| jabberd2 | jabberd2 | >= 0 < 2.2.8-2.1 | 2.2.8-2.1 |
| jabberd2 | jabberd2 | >= 0 < 2.2.8-2.1 | 2.2.8-2.1 |
| jabberd2 | jabberd2 | >= 0 < 2.2.8-2.1 | 2.2.8-2.1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rpcf-xw9j-7c7j: jabberd2 before 2
ghsa_unreviewed·2022-05-17·CVSS 6.5
CVE-2011-1755 [MEDIUM] CWE-776 GHSA-rpcf-xw9j-7c7j: jabberd2 before 2
jabberd2 before 2.2.14 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
OSV
CVE-2011-1755: jabberd2 before 2
osv·2011-06-21·CVSS 6.5
CVE-2011-1755 [MEDIUM] CVE-2011-1755: jabberd2 before 2
jabberd2 before 2.2.14 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
Red Hat
jabberd: DoS via the XML "billion laughs attack"
vendor_redhat·2011-05-31·CVSS 6.5
CVE-2011-1755 [MEDIUM] jabberd: DoS via the XML "billion laughs attack"
jabberd: DoS via the XML "billion laughs attack"
jabberd2 before 2.2.14 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
Statement: Vulnerable. This issue has been addressed in Red Hat Network Satellite Server v 5.4.1 via RHSA-2011:0882 https://rhn.redhat.com/errata/RHSA-2011-0882.html and in Red Hat Network Proxy Server v5.4.1 via RHSA-2011:0881 https://rhn.redhat.com/errata/RHSA-2011-0881.html. This issue is not planned
to be fixed in Red Hat Network Satellite Server versions 5.0.2, 5.1.1, 5.2.1, 5.3.0 and not planned to be fixed in Red Hat Network Proxy Server versions 5.0.
Debian
CVE-2011-1755: jabberd2 - jabberd2 before 2.2.14 does not properly detect recursion during entity expansio...
vendor_debian·2011·CVSS 6.5
CVE-2011-1755 [MEDIUM] CVE-2011-1755: jabberd2 - jabberd2 before 2.2.14 does not properly detect recursion during entity expansio...
jabberd2 before 2.2.14 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
Scope: local
bookworm: resolved (fixed in 2.2.8-2.1)
bullseye: resolved (fixed in 2.2.8-2.1)
forky: resolved (fixed in 2.2.8-2.1)
sid: resolved (fixed in 2.2.8-2.1)
trixie: resolved (fixed in 2.2.8-2.1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-1755 jabberd: DoS via the XML "billion laughs attack" [epel-5]
bugzilla·2011-06-01·CVSS 7.5
CVE-2011-1755 [HIGH] CVE-2011-1755 jabberd: DoS via the XML "billion laughs attack" [epel-5]
CVE-2011-1755 jabberd: DoS via the XML "billion laughs attack" [epel-5]
epel-5 tracking bug for jabberd: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
Backported the fix for EPEL-5:
https://admin.fedoraproject.org/updates/jabberd-2.2.11-3.el5
Bugzilla
CVE-2011-1755 jabberd: DoS via the XML "billion laughs attack" [fedora-all]
bugzilla·2011-06-01·CVSS 7.5
CVE-2011-1755 [HIGH] CVE-2011-1755 jabberd: DoS via the XML "billion laughs attack" [fedora-all]
CVE-2011-1755 jabberd: DoS via the XML "billion laughs attack" [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=700390
Please note: this issue affects multipl
Bugzilla
CVE-2011-1755 jabberd: DoS via the XML "billion laughs attack" [epel-6]
bugzilla·2011-06-01·CVSS 7.5
CVE-2011-1755 [HIGH] CVE-2011-1755 jabberd: DoS via the XML "billion laughs attack" [epel-6]
CVE-2011-1755 jabberd: DoS via the XML "billion laughs attack" [epel-6]
epel-6 tracking bug for jabberd: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
An update for EPEL 6 is requested:
https://admin.fedoraproject.org/updates/jabberd-2.2.14-1.el6
Bugzilla
CVE-2011-1755 jabberd: DoS via the XML "billion laughs attack"
bugzilla·2011-04-28·CVSS 7.5
CVE-2011-1755 [HIGH] CVE-2011-1755 jabberd: DoS via the XML "billion laughs attack"
CVE-2011-1755 jabberd: DoS via the XML "billion laughs attack"
jabberd2, when expat is used, do not properly detect recursion
during entity expansion, which allows context-dependent attackers
to cause a denial of service (memory and CPU consumption) via a
crafted XML document containing a large number of nested entity
references, aka the "billion laughs attack."
References:
[1] http://en.wikipedia.org/wiki/Billion_laughs
[2] http://www.webcitation.org/5wwJidGdh
Discussion:
This issue affects the versions of the jabberd package, as present
within EPEL-5 and EPEL-6 repositories.
This issue affects the versions of the jabberd package, as shipped
with Fedora release of 13 and 14.
---
The CVE identifier of CVE-2011-1755 has been assigned to this issue.
---
Created attachment 496732
Pro
http://codex.xiaoka.com/svn/jabberd2/tags/jabberd-2.2.14/ChangeLoghttp://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-June/061341.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-June/061458.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-June/061482.htmlhttp://secunia.com/advisories/44787http://secunia.com/advisories/44957http://secunia.com/advisories/45112http://support.apple.com/kb/HT5002http://www.mail-archive.com/jabberd2%40lists.xiaoka.com/msg01655.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0881.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0882.htmlhttp://www.securityfocus.com/bid/48250https://bugzilla.redhat.com/show_bug.cgi?id=700390https://exchange.xforce.ibmcloud.com/vulnerabilities/67770https://hermes.opensuse.org/messages/9197650http://codex.xiaoka.com/svn/jabberd2/tags/jabberd-2.2.14/ChangeLoghttp://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-June/061341.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-June/061458.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-June/061482.htmlhttp://secunia.com/advisories/44787http://secunia.com/advisories/44957http://secunia.com/advisories/45112http://support.apple.com/kb/HT5002http://www.mail-archive.com/jabberd2%40lists.xiaoka.com/msg01655.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0881.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0882.htmlhttp://www.securityfocus.com/bid/48250https://bugzilla.redhat.com/show_bug.cgi?id=700390https://exchange.xforce.ibmcloud.com/vulnerabilities/67770https://hermes.opensuse.org/messages/9197650
2011-06-21
Published