oss-sec mailing list archives

Re: CVE request: ejabberd before 2.1.9


From: Kurt Seifried <kseifried () redhat com>
Date: Sat, 19 Nov 2011 12:35:39 -0700

On 11/19/2011 04:18 AM, Hanno Böck wrote:
Hi,

From
http://www.process-one.net/en/ejabberd/release_notes/release_note_ejabberd_2.1.9

This looks like its security-relevant:
- Fix Denial of Service when user sends malformed publish stanza
  (EJAB-1498)

Upstream bug report:
https://support.process-one.net/browse/EJAB-1498


Please use CVE-2011-4320  for this issue.

-- 

-Kurt Seifried / Red Hat Security Response Team


Current thread: