OpenBSD VuXML: Documenting security issues in the OpenBSD Ports & Packages Collection

jabberd -- buffer overflow vulnerabilities

Affected packages
jabberd < 2.0s9

Details

VuXML ID e362ef7a-043d-11da-a2dc-000b5d77b0f5
Discovery 2005-08-01
Entry 2005-08-02

Michael has reported some vulnerabilities in jabberd, which potentially can be exploited by malicious users to compromise a vulnerable system.

The vulnerabilities are caused due to three boundary errors in jid.c when parsing JID strings with overly long user, host, or resource components. This can be exploited to crash the server or potentially execute arbitrary code.

References

URL http://secunia.com/advisories/16291/