Debian Lua-Expat vulnerabilities
2 known vulnerabilities affecting debian/lua-expat.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1LOW1
Vulnerabilities
Page 1 of 1
CVE-2014-2744HIGHCVSS 7.8fixed in lua-expat 1.3.0-1 (bookworm)2014
CVE-2014-2744 [HIGH] CVE-2014-2744: lua-expat - plugins/mod_compression.lua in (1) Prosody before 0.9.4 and (2) Lightwitch Metro...
plugins/mod_compression.lua in (1) Prosody before 0.9.4 and (2) Lightwitch Metronome through 3.4 negotiates stream compression while a session is unauthenticated, which allows remote attackers to cause a denial of service (resource consumption) via compressed XML elements in an XMPP stream, aka an "xmppbomb" attack.
Scope: local
bookworm: resolved (fixed in 1.3.0-1)
debian
CVE-2011-2188LOWCVSS 6.5fixed in lua-expat 1.2.0-1 (bookworm)2011
CVE-2011-2188 [MEDIUM] CVE-2011-2188: lua-expat - LuaExpat before 1.2.0 does not properly detect recursion during entity expansion...
LuaExpat before 1.2.0 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
Scope: local
bookworm: resolved (fixed in 1.2.0-1)
bullseye: resolved (fixed in
debian