← Back

CVE-2014-2745

nvd nist
Published: Apr 11, 2014Modified: May 6, 2026

JSON object

Loading...
7.8
Vector
AV:N/AC:L/Au:N/C:N/I:N/A:C
Exploitability: 10.0 / Impact: 6.9
Source: NVD

Description

Prosody before 0.9.4 does not properly restrict the processing of compressed XML elements, which allows remote attackers to cause a denial of service (resource consumption) via a crafted XMPP stream, aka an "xmppbomb" attack, related to core/portmanager.lua and util/xmppstream.lua.

Affected (20)

Products: Prosody: Prosody
1 product
Prosody
Configuration A
20 vulnerable
Vulnerable SoftwareAffected Versions
Prosody
Up to 0.9.3
Version 0.1.0
Version 0.2.0
Version 0.3.0
Version 0.4.0
Version 0.4.1
Version 0.4.2
Version 0.5.0
Version 0.5.1
Version 0.5.2
Version 0.6.0
Version 0.6.1
Version 0.6.2
Version 0.7.0
Version 0.8.0
Version 0.8.1
Version 0.8.2
Version 0.9.0
Version 0.9.1
Version 0.9.2

Related CWEs

References (16)

Source: security@debian.org
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.