mirror of
https://github.com/fkie-cad/nvd-json-data-feeds.git
synced 2025-07-29 05:56:17 +00:00
329 lines
12 KiB
JSON
329 lines
12 KiB
JSON
{
|
|
"id": "CVE-2011-1755",
|
|
"sourceIdentifier": "secalert@redhat.com",
|
|
"published": "2011-06-21T02:52:43.373",
|
|
"lastModified": "2017-08-17T01:34:22.480",
|
|
"vulnStatus": "Modified",
|
|
"descriptions": [
|
|
{
|
|
"lang": "en",
|
|
"value": "jabberd2 before 2.2.14 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564."
|
|
},
|
|
{
|
|
"lang": "es",
|
|
"value": "jabberd2 antes de v2.2.14 no detecta correctamente la recursividad durante la expansi\u00f3n de la entidad, lo que permite a atacantes remotos provocar una denegaci\u00f3n de servicio ( consumo de memoria y CPU ) a trav\u00e9s de un documento XML manipulado que contiene un gran n\u00famero de referencias a entidades anidadas, un problema similar a CVE-2003-1564."
|
|
}
|
|
],
|
|
"metrics": {
|
|
"cvssMetricV2": [
|
|
{
|
|
"source": "nvd@nist.gov",
|
|
"type": "Primary",
|
|
"cvssData": {
|
|
"version": "2.0",
|
|
"vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
|
|
"accessVector": "NETWORK",
|
|
"accessComplexity": "LOW",
|
|
"authentication": "NONE",
|
|
"confidentialityImpact": "NONE",
|
|
"integrityImpact": "NONE",
|
|
"availabilityImpact": "PARTIAL",
|
|
"baseScore": 5.0
|
|
},
|
|
"baseSeverity": "MEDIUM",
|
|
"exploitabilityScore": 10.0,
|
|
"impactScore": 2.9,
|
|
"acInsufInfo": false,
|
|
"obtainAllPrivilege": false,
|
|
"obtainUserPrivilege": false,
|
|
"obtainOtherPrivilege": false,
|
|
"userInteractionRequired": false
|
|
}
|
|
]
|
|
},
|
|
"weaknesses": [
|
|
{
|
|
"source": "nvd@nist.gov",
|
|
"type": "Primary",
|
|
"description": [
|
|
{
|
|
"lang": "en",
|
|
"value": "CWE-399"
|
|
}
|
|
]
|
|
}
|
|
],
|
|
"configurations": [
|
|
{
|
|
"nodes": [
|
|
{
|
|
"operator": "OR",
|
|
"negate": false,
|
|
"cpeMatch": [
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:jabber:jabberd2:*:*:*:*:*:*:*:*",
|
|
"versionEndIncluding": "2.2.13",
|
|
"matchCriteriaId": "AD890FA2-01A4-43A4-A5F6-F9288E516F31"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:jabber:jabberd2:2.1:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "9873649C-2363-47A7-B076-E122B3CD5B7B"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:jabber:jabberd2:2.1.1:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "EC0068D4-4F95-4615-A832-9958C7E4A134"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:jabber:jabberd2:2.1.2:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "D72F8726-45A9-4EE0-9B84-039CBD970F92"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:jabber:jabberd2:2.1.3:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "DF545EA1-4388-48E6-8B83-472192D59E83"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:jabber:jabberd2:2.1.4:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "B414FC21-9B19-4B5C-BAE5-BAFD52C18F71"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:jabber:jabberd2:2.1.5:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "0AE94740-E7D8-4AB4-96D1-B66856A87C51"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:jabber:jabberd2:2.1.6:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "D3C0D595-398E-43D0-94DE-E72023DF1D85"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:jabber:jabberd2:2.1.7:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "5D42EB3A-056C-4013-AF4C-1EF5171D9FC2"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:jabber:jabberd2:2.1.8:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "DA6E42C2-A103-4AB8-9E95-30897C312C79"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:jabber:jabberd2:2.1.9:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "C1CD780F-3434-46C2-A302-E47D5D1793C0"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:jabber:jabberd2:2.1.10:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "2FBE6AC0-6F6C-40F6-A2F7-D032D3649511"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:jabber:jabberd2:2.1.11:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "B3073D08-B342-4836-92BC-C51920621078"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:jabber:jabberd2:2.1.12:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "6772C65F-C429-4AE1-803B-E9A8BF551513"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:jabber:jabberd2:2.1.13:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "62311FFF-5E10-4E59-BE62-9368CE39BAA1"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:jabber:jabberd2:2.1.14:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "B4DDEB65-E090-4B05-B666-E574CBAF3F8E"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:jabber:jabberd2:2.1.15:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "29BDD799-B16E-4A29-A171-FD613D3C4F1C"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:jabber:jabberd2:2.1.16:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "1D468B00-AABD-44D3-844F-6F57E81DFAFA"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:jabber:jabberd2:2.1.17:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "259368E4-ECA5-431A-85F6-4048A858829C"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:jabber:jabberd2:2.1.18:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "1CD24F6A-24DB-4BC6-9D3C-2A186FCC5012"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:jabber:jabberd2:2.1.19:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "B3E82A2E-5C79-4554-8639-C9266F721CB9"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:jabber:jabberd2:2.1.20:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "932F2C19-28E9-44B3-B60B-67EF64662EFF"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:jabber:jabberd2:2.1.21:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "6DDC6FEE-CE94-4E1D-88CD-756C4CBCACED"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:jabber:jabberd2:2.1.22:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "D4941D35-1DEE-4828-AF45-155B093CAB5A"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:jabber:jabberd2:2.1.23:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "B4EFCBCF-7E0D-4200-92D8-C11E45BF2AA5"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:jabber:jabberd2:2.1.24:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "6BD4E7FB-74E8-42A5-884C-0CA40646DD71"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:jabber:jabberd2:2.2.0:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "5C7E0462-0418-4F26-9D0C-61DA8ADF87BF"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:jabber:jabberd2:2.2.1:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "B83E514E-8F3E-4144-90A2-873CB8C01368"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:jabber:jabberd2:2.2.2:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "67030AEE-402A-4347-9AF6-3BBFB8F91582"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:jabber:jabberd2:2.2.3:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "C2CDD3EB-EA96-4333-B434-AF9215B62B90"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:jabber:jabberd2:2.2.4:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "5BAEF1C2-2E5A-4B4C-9F0C-B7DFE11AF9D3"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:jabber:jabberd2:2.2.5:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "10098837-6E13-4CDF-B798-60E44DFA9E67"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:jabber:jabberd2:2.2.6:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "A67E6019-EC4B-4764-80BA-E0030BB624B1"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:jabber:jabberd2:2.2.7:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "286C4505-DF71-4C63-823B-59239EE41014"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:jabber:jabberd2:2.2.7.1:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "910EEBC0-FF16-4370-81E3-B66671DC3340"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:jabber:jabberd2:2.2.8:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "425FE7D0-F96F-444B-A584-DD3ACA84D041"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:jabber:jabberd2:2.2.9:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "23D859D0-C999-48B3-9B13-546C6E68AF52"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:jabber:jabberd2:2.2.10:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "CB8442A6-5F9E-4AD2-BA8F-2978F22EFB28"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:jabber:jabberd2:2.2.11:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "0C485C6F-C0CE-4F9B-9C59-93E2E6CF91A7"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:jabber:jabberd2:2.2.12:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "E5B8973D-5CE8-477C-B330-5D9BA8D3DA59"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
}
|
|
],
|
|
"references": [
|
|
{
|
|
"url": "http://codex.xiaoka.com/svn/jabberd2/tags/jabberd-2.2.14/ChangeLog",
|
|
"source": "secalert@redhat.com"
|
|
},
|
|
{
|
|
"url": "http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html",
|
|
"source": "secalert@redhat.com"
|
|
},
|
|
{
|
|
"url": "http://lists.fedoraproject.org/pipermail/package-announce/2011-June/061341.html",
|
|
"source": "secalert@redhat.com"
|
|
},
|
|
{
|
|
"url": "http://lists.fedoraproject.org/pipermail/package-announce/2011-June/061458.html",
|
|
"source": "secalert@redhat.com"
|
|
},
|
|
{
|
|
"url": "http://lists.fedoraproject.org/pipermail/package-announce/2011-June/061482.html",
|
|
"source": "secalert@redhat.com"
|
|
},
|
|
{
|
|
"url": "http://support.apple.com/kb/HT5002",
|
|
"source": "secalert@redhat.com"
|
|
},
|
|
{
|
|
"url": "http://www.mail-archive.com/jabberd2@lists.xiaoka.com/msg01655.html",
|
|
"source": "secalert@redhat.com",
|
|
"tags": [
|
|
"Patch"
|
|
]
|
|
},
|
|
{
|
|
"url": "http://www.redhat.com/support/errata/RHSA-2011-0881.html",
|
|
"source": "secalert@redhat.com"
|
|
},
|
|
{
|
|
"url": "http://www.redhat.com/support/errata/RHSA-2011-0882.html",
|
|
"source": "secalert@redhat.com"
|
|
},
|
|
{
|
|
"url": "http://www.securityfocus.com/bid/48250",
|
|
"source": "secalert@redhat.com"
|
|
},
|
|
{
|
|
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=700390",
|
|
"source": "secalert@redhat.com",
|
|
"tags": [
|
|
"Patch"
|
|
]
|
|
},
|
|
{
|
|
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/67770",
|
|
"source": "secalert@redhat.com"
|
|
},
|
|
{
|
|
"url": "https://hermes.opensuse.org/messages/9197650",
|
|
"source": "secalert@redhat.com"
|
|
}
|
|
]
|
|
} |