Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS01djV3LTQ0dzYtcTVods4AAepF

Erlang Solutions MongooseIM vulnerable to denial of service (DoS) via crafted XMPP stream

Erlang Solutions MongooseIM through 1.3.1 rev. 2 does not properly restrict the processing of compressed XML elements, which allows remote attackers to cause a denial of service (resource consumption) via a crafted XMPP stream, aka an "xmppbomb" attack.

Permalink: https://github.com/advisories/GHSA-5v5w-44w6-q5hv
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS01djV3LTQ0dzYtcTVods4AAepF
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: almost 2 years ago
Updated: about 1 year ago


Identifiers: GHSA-5v5w-44w6-q5hv, CVE-2014-2829
References: Repository: https://github.com/esl/MongooseIM
Blast Radius: 1.0

Affected Packages

hex:MongooseIM
Affected Version Ranges: <= 1.3.1
Fixed in: 1.3.2