ejabberd_c2s.erl in ejabberd prior to 2.1.3 allows remote malicious users to cause a denial of service (daemon crash) via a large number of c2s (aka client2server) messages that trigger a queue overload.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
process-one ejabberd 1.1.2 |
||
process-one ejabberd 0.9.8 |
||
process-one ejabberd 2.0.2 |
||
process-one ejabberd 2.0.1_2 |
||
process-one ejabberd 2.1.1 |
||
process-one ejabberd 2.0.3 |
||
process-one ejabberd 0.9.1 |
||
process-one ejabberd 1.1.1.0 |
||
process-one ejabberd 1.1.1.1 |
||
process-one ejabberd 2.0.0 |
||
process-one ejabberd |
||
process-one ejabberd 2.1.0 |
||
process-one ejabberd 1.0.0 |
||
process-one ejabberd 0.9 |
||
process-one ejabberd 1.1.3 |
||
process-one ejabberd 2.0.5 |
||
process-one ejabberd 2.0.4 |
||
process-one ejabberd 1.1.0 |
||
process-one ejabberd 1.1.1 |
||
process-one ejabberd 1.1.14 |