cbcvebase.
CVE-2011-1755
published 2011-06-21

CVE-2011-1755: jabberd2 before 2.2.14 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU…

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
jabberd2 before 2.2.14 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.

Affected

13 ranges
VendorProductVersion rangeFixed in
applemac_os_x< 10.6.810.6.8
applemac_os_x>= 10.7.0 < 10.7.210.7.2
applemac_os_x_server< 10.6.810.6.8
applemac_os_x_server>= 10.7.0 < 10.7.210.7.2
debianjabberd2< jabberd2 2.2.8-2.1 (bookworm)jabberd2 2.2.8-2.1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
jabberd2jabberd2< 2.2.142.2.14
jabberd2jabberd2>= 0 < 2.2.8-2.12.2.8-2.1
jabberd2jabberd2>= 0 < 2.2.8-2.12.2.8-2.1
jabberd2jabberd2>= 0 < 2.2.8-2.12.2.8-2.1
jabberd2jabberd2>= 0 < 2.2.8-2.12.2.8-2.1

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv6.5MEDIUM