Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Possible DoS attack against jabberd 1.4.3 and jadc2s 0.9.0 |
|---|---|
| Date: | Mon, 20 Sep 2004 11:51:22 +0200 |
jabberd up to and including version 1.4.3 and jadc2s up to and including version 0.9.0 are vulnerable against a DoS attack reported by Jose Antonio Calvo yesterday on the jabberd mailing list. (http://jabberstudio.org/pipermail/jabberd/2004-September/002004.html) An attacker can crash a running jabberd14 server, if it has access to one of the following types of network sockets: - Socket accepting client connections - Socket accepting connections from other servers - Socket connecting to an other Jabber server - Socket accepting connections from server components - Socket connecting to server components (All connections on which XML is parsed by jabberd14.) An attacker can crash a running jadc2s component, if it has access to on of the following types of network sockets: - Socket accepting client connections - Socket connecting to the main Jabber server (All connections on which XML is parsed by jadc2s.) The attack can be tested by sending the byte sequence 0xEF, 0xBB, 0xBF to any of the above sockets. The bug has been fixed in the CVS versions of both projects already some time ago as the affected code already had been removed from both projects. Therefore you are not affected if you are running CVS snapshots that are newer than 2004-05-22 (jabberd14) or 2004-09-07 (jadc2s). A patch for jabberd 1.4.3 is available at the URI http://devel.amessage.info/jabberd14/, a patch for jadc2s has not yet been published but will be available on http://devel.amessage.info/jadc2s/ shortly. Related software: - jabberd2 version 2.0s3 is not affected by this bug. - Other projects, that incorporate jabberd14 code might be affected by this bug as well. This might include the Jabber module of CenterICQ (only vulnerable by a Jabber server CenterICQ connects to), but I have not tested this yet.
signature.asc
Description: Digital signature
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: Diebold Global Election Management System (GEMS) Backdoor Account Allows Authenticated Users to Modify Votes, steve menard |
|---|---|
| Next by Date: | Re: Diebold Global Election Management System (GEMS) Backdoor Account Allows Authenticated Users to Modify Votes, Gene Cronk |
| Previous by Thread: | [Full-Disclosure] [ GLSA 200409-31 ] jabberd 1.x: Denial of Service vulnerability, Sune Kloppenborg Jeppesen |
| Next by Thread: | Multiple Vulnerabilities in Symantec Enterprise Firewall/Gateway Security Products, Mike Sues |
| Indexes: | [Date] [Thread] [Top] [All Lists] |