CVE-2011-1754

jabberd14 <= 1.6.1.1 - Denial of Service via XML Entity Expansion

Title source: llm
STIX 2.1

Description

jabberd14 1.6.1.1 and earlier does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.

References (5)

Core 5
Core References
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2011/dsa-2249
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/44795
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/67771
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/48070

Scores

EPSS 0.0227
EPSS Percentile 81.1%

Details

CWE
CWE-399
Status published
Products (8)
jabberd/jabberd14 1.4.1
jabberd/jabberd14 1.4.2
jabberd/jabberd14 1.4.3
jabberd/jabberd14 1.4.3.1
jabberd/jabberd14 1.4.4
jabberd/jabberd14 1.6.0
jabberd/jabberd14 1.6.1
jabberd/jabberd14 < 1.6.1.1
Published Jun 21, 2011
Tracked Since Feb 18, 2026