FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2004-1378

This CVE name corresponds to:

Entered Topic
2004-12-26 jabberd -- denial-of-service vulnerability

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2004-1378
Phase Assigned(20050119)

Description

The expat XML parser code, as used in the open source Jabber (jabberd) 1.4.3 and earlier, jadc2s 0.9.0 and earlier, and possibly other packages, allows remote attackers to cause a denial of service (application crash) via a malformed packet to a socket that accepts XML connections.

References

Source Reference
BUGTRAQ 20040920 Possible DoS attack against jabberd 1.4.3 and jadc2s 0.9.0
MLIST [jabberd] 20040919 Jabberd 1.4 critical bug
CONFIRM http://devel.amessage.info/jabberd14/
CONFIRM http://www.vuxml.org/freebsd/2e25d38b-54d1-11d9-b612-000c6e8f12ef.html
GENTOO GLSA-200409-31
BID 11231
OSVDB 10257
SECTRACK 1011383
SECTRACK 1011384
SECUNIA 12636
XF jadc2s-xml-dos(17467)
XF jabberd-xml-dos(17466)