René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

329 lines
12 KiB
JSON

{
"id": "CVE-2011-1755",
"sourceIdentifier": "secalert@redhat.com",
"published": "2011-06-21T02:52:43.373",
"lastModified": "2017-08-17T01:34:22.480",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "jabberd2 before 2.2.14 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564."
},
{
"lang": "es",
"value": "jabberd2 antes de v2.2.14 no detecta correctamente la recursividad durante la expansi\u00f3n de la entidad, lo que permite a atacantes remotos provocar una denegaci\u00f3n de servicio ( consumo de memoria y CPU ) a trav\u00e9s de un documento XML manipulado que contiene un gran n\u00famero de referencias a entidades anidadas, un problema similar a CVE-2003-1564."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"availabilityImpact": "PARTIAL",
"baseScore": 5.0
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 10.0,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-399"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:jabber:jabberd2:*:*:*:*:*:*:*:*",
"versionEndIncluding": "2.2.13",
"matchCriteriaId": "AD890FA2-01A4-43A4-A5F6-F9288E516F31"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:jabber:jabberd2:2.1:*:*:*:*:*:*:*",
"matchCriteriaId": "9873649C-2363-47A7-B076-E122B3CD5B7B"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:jabber:jabberd2:2.1.1:*:*:*:*:*:*:*",
"matchCriteriaId": "EC0068D4-4F95-4615-A832-9958C7E4A134"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:jabber:jabberd2:2.1.2:*:*:*:*:*:*:*",
"matchCriteriaId": "D72F8726-45A9-4EE0-9B84-039CBD970F92"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:jabber:jabberd2:2.1.3:*:*:*:*:*:*:*",
"matchCriteriaId": "DF545EA1-4388-48E6-8B83-472192D59E83"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:jabber:jabberd2:2.1.4:*:*:*:*:*:*:*",
"matchCriteriaId": "B414FC21-9B19-4B5C-BAE5-BAFD52C18F71"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:jabber:jabberd2:2.1.5:*:*:*:*:*:*:*",
"matchCriteriaId": "0AE94740-E7D8-4AB4-96D1-B66856A87C51"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:jabber:jabberd2:2.1.6:*:*:*:*:*:*:*",
"matchCriteriaId": "D3C0D595-398E-43D0-94DE-E72023DF1D85"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:jabber:jabberd2:2.1.7:*:*:*:*:*:*:*",
"matchCriteriaId": "5D42EB3A-056C-4013-AF4C-1EF5171D9FC2"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:jabber:jabberd2:2.1.8:*:*:*:*:*:*:*",
"matchCriteriaId": "DA6E42C2-A103-4AB8-9E95-30897C312C79"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:jabber:jabberd2:2.1.9:*:*:*:*:*:*:*",
"matchCriteriaId": "C1CD780F-3434-46C2-A302-E47D5D1793C0"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:jabber:jabberd2:2.1.10:*:*:*:*:*:*:*",
"matchCriteriaId": "2FBE6AC0-6F6C-40F6-A2F7-D032D3649511"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:jabber:jabberd2:2.1.11:*:*:*:*:*:*:*",
"matchCriteriaId": "B3073D08-B342-4836-92BC-C51920621078"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:jabber:jabberd2:2.1.12:*:*:*:*:*:*:*",
"matchCriteriaId": "6772C65F-C429-4AE1-803B-E9A8BF551513"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:jabber:jabberd2:2.1.13:*:*:*:*:*:*:*",
"matchCriteriaId": "62311FFF-5E10-4E59-BE62-9368CE39BAA1"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:jabber:jabberd2:2.1.14:*:*:*:*:*:*:*",
"matchCriteriaId": "B4DDEB65-E090-4B05-B666-E574CBAF3F8E"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:jabber:jabberd2:2.1.15:*:*:*:*:*:*:*",
"matchCriteriaId": "29BDD799-B16E-4A29-A171-FD613D3C4F1C"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:jabber:jabberd2:2.1.16:*:*:*:*:*:*:*",
"matchCriteriaId": "1D468B00-AABD-44D3-844F-6F57E81DFAFA"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:jabber:jabberd2:2.1.17:*:*:*:*:*:*:*",
"matchCriteriaId": "259368E4-ECA5-431A-85F6-4048A858829C"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:jabber:jabberd2:2.1.18:*:*:*:*:*:*:*",
"matchCriteriaId": "1CD24F6A-24DB-4BC6-9D3C-2A186FCC5012"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:jabber:jabberd2:2.1.19:*:*:*:*:*:*:*",
"matchCriteriaId": "B3E82A2E-5C79-4554-8639-C9266F721CB9"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:jabber:jabberd2:2.1.20:*:*:*:*:*:*:*",
"matchCriteriaId": "932F2C19-28E9-44B3-B60B-67EF64662EFF"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:jabber:jabberd2:2.1.21:*:*:*:*:*:*:*",
"matchCriteriaId": "6DDC6FEE-CE94-4E1D-88CD-756C4CBCACED"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:jabber:jabberd2:2.1.22:*:*:*:*:*:*:*",
"matchCriteriaId": "D4941D35-1DEE-4828-AF45-155B093CAB5A"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:jabber:jabberd2:2.1.23:*:*:*:*:*:*:*",
"matchCriteriaId": "B4EFCBCF-7E0D-4200-92D8-C11E45BF2AA5"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:jabber:jabberd2:2.1.24:*:*:*:*:*:*:*",
"matchCriteriaId": "6BD4E7FB-74E8-42A5-884C-0CA40646DD71"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:jabber:jabberd2:2.2.0:*:*:*:*:*:*:*",
"matchCriteriaId": "5C7E0462-0418-4F26-9D0C-61DA8ADF87BF"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:jabber:jabberd2:2.2.1:*:*:*:*:*:*:*",
"matchCriteriaId": "B83E514E-8F3E-4144-90A2-873CB8C01368"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:jabber:jabberd2:2.2.2:*:*:*:*:*:*:*",
"matchCriteriaId": "67030AEE-402A-4347-9AF6-3BBFB8F91582"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:jabber:jabberd2:2.2.3:*:*:*:*:*:*:*",
"matchCriteriaId": "C2CDD3EB-EA96-4333-B434-AF9215B62B90"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:jabber:jabberd2:2.2.4:*:*:*:*:*:*:*",
"matchCriteriaId": "5BAEF1C2-2E5A-4B4C-9F0C-B7DFE11AF9D3"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:jabber:jabberd2:2.2.5:*:*:*:*:*:*:*",
"matchCriteriaId": "10098837-6E13-4CDF-B798-60E44DFA9E67"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:jabber:jabberd2:2.2.6:*:*:*:*:*:*:*",
"matchCriteriaId": "A67E6019-EC4B-4764-80BA-E0030BB624B1"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:jabber:jabberd2:2.2.7:*:*:*:*:*:*:*",
"matchCriteriaId": "286C4505-DF71-4C63-823B-59239EE41014"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:jabber:jabberd2:2.2.7.1:*:*:*:*:*:*:*",
"matchCriteriaId": "910EEBC0-FF16-4370-81E3-B66671DC3340"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:jabber:jabberd2:2.2.8:*:*:*:*:*:*:*",
"matchCriteriaId": "425FE7D0-F96F-444B-A584-DD3ACA84D041"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:jabber:jabberd2:2.2.9:*:*:*:*:*:*:*",
"matchCriteriaId": "23D859D0-C999-48B3-9B13-546C6E68AF52"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:jabber:jabberd2:2.2.10:*:*:*:*:*:*:*",
"matchCriteriaId": "CB8442A6-5F9E-4AD2-BA8F-2978F22EFB28"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:jabber:jabberd2:2.2.11:*:*:*:*:*:*:*",
"matchCriteriaId": "0C485C6F-C0CE-4F9B-9C59-93E2E6CF91A7"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:jabber:jabberd2:2.2.12:*:*:*:*:*:*:*",
"matchCriteriaId": "E5B8973D-5CE8-477C-B330-5D9BA8D3DA59"
}
]
}
]
}
],
"references": [
{
"url": "http://codex.xiaoka.com/svn/jabberd2/tags/jabberd-2.2.14/ChangeLog",
"source": "secalert@redhat.com"
},
{
"url": "http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html",
"source": "secalert@redhat.com"
},
{
"url": "http://lists.fedoraproject.org/pipermail/package-announce/2011-June/061341.html",
"source": "secalert@redhat.com"
},
{
"url": "http://lists.fedoraproject.org/pipermail/package-announce/2011-June/061458.html",
"source": "secalert@redhat.com"
},
{
"url": "http://lists.fedoraproject.org/pipermail/package-announce/2011-June/061482.html",
"source": "secalert@redhat.com"
},
{
"url": "http://support.apple.com/kb/HT5002",
"source": "secalert@redhat.com"
},
{
"url": "http://www.mail-archive.com/jabberd2@lists.xiaoka.com/msg01655.html",
"source": "secalert@redhat.com",
"tags": [
"Patch"
]
},
{
"url": "http://www.redhat.com/support/errata/RHSA-2011-0881.html",
"source": "secalert@redhat.com"
},
{
"url": "http://www.redhat.com/support/errata/RHSA-2011-0882.html",
"source": "secalert@redhat.com"
},
{
"url": "http://www.securityfocus.com/bid/48250",
"source": "secalert@redhat.com"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=700390",
"source": "secalert@redhat.com",
"tags": [
"Patch"
]
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/67770",
"source": "secalert@redhat.com"
},
{
"url": "https://hermes.opensuse.org/messages/9197650",
"source": "secalert@redhat.com"
}
]
}