5

CVE-2004-1378

The expat XML parser code, as used in the open source Jabber (jabberd) 1.4.3 and earlier, jadc2s 0.9.0 and earlier, and possibly other packages, allows remote attackers to cause a denial of service (application crash) via a malformed packet to a socket that accepts XML connections.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
JabberstudioJabberd Version1.4
JabberstudioJabberd Version1.4.1
JabberstudioJabberd Version1.4.2
JabberstudioJabberd Version1.4.2a
JabberstudioJabberd Version1.4.3
JabberstudioJadc2s Version0.6
JabberstudioJadc2s Version0.7
JabberstudioJadc2s Version0.8
JabberstudioJadc2s Version0.9
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.44% 0.822
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://devel.amessage.info/jabberd14/
Patch
http://mail.jabber.org/pipermail/jabberd/2004-September/002004.html
http://marc.info/?l=bugtraq&m=109583829122679&w=2
http://secunia.com/advisories/12636
http://securitytracker.com/id?1011383
http://securitytracker.com/id?1011384
http://www.gentoo.org/security/en/glsa/glsa-200409-31.xml
Patch
http://www.osvdb.org/10257
http://www.securityfocus.com/bid/11231
Patch
http://www.vuxml.org/freebsd/2e25d38b-54d1-11d9-b612-000c6e8f12ef.html
https://exchange.xforce.ibmcloud.com/vulnerabilities/17466
https://exchange.xforce.ibmcloud.com/vulnerabilities/17467