VDB
CVE-2011-1753
CVE-2011-1753
PUBLISHED
CVSS 5 MEDIUM
expat_erl.c in ejabberd before 2.1.7 and 3.x before 3.0.0-alpha-3, and exmpp before 0.9.7, does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
EPSS 1.94% · 83.8th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
1.94%
83.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| process-one | ejabberd | 1.0.0, 2.1.2, 0 |
| process-one | exmpp | 0, 0.9.1, 0.9.2 |
| n/a | n/a | n/a |
Timeline
- Jun 1, 2011 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
References
- ejabberd-xml-dos(67769) vdb
- DSA-2248 vendor-advisory
- http://www.process-one.net/en/ejabberd/release_notes/release_note_ejabberd_2.1.7/ url
- 44765 third-party-advisory
- https://git.process-one.net/ejabberd/mainline/commit/bd1df027c622e1f96f9eeaac612a6a956c1ff0b6 url
- FEDORA-2011-8415 vendor-advisory
- http://www.ejabberd.im/ejabberd-2.1.7 url
- https://bugzilla.redhat.com/show_bug.cgi?id=700454 url
- 44807 third-party-advisory
- 48072 vdb
- FEDORA-2011-8437 vendor-advisory
- 45120 third-party-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2011-1753 advisory
- http://www.process-one.net/en/ejabberd/release_notes/release_note_ejabberd_2.1.7 url