CVE-2011-1754
jabberd14 <= 1.6.1.1 - Denial of Service via XML Entity Expansion
Title source: llmDescription
jabberd14 1.6.1.1 and earlier does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
References (5)
Core 5
Core References
Various Sources x_refsource_confirm
http://packages.debian.org/changelogs/pool/main/j/jabberd14/jabberd14_1.6.1.1-5+squeeze1/changelog
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2011/dsa-2249
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/44795
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/67771
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/48070
Scores
EPSS
0.0227
EPSS Percentile
81.2%
Details
CWE
CWE-399
Status
published
Products (8)
jabberd/jabberd14
1.4.1
jabberd/jabberd14
1.4.2
jabberd/jabberd14
1.4.3
jabberd/jabberd14
1.4.3.1
jabberd/jabberd14
1.4.4
jabberd/jabberd14
1.6.0
jabberd/jabberd14
1.6.1
jabberd/jabberd14
< 1.6.1.1
Published
Jun 21, 2011
Tracked Since
Feb 18, 2026