jabberd SSL Connection Handling Flaw May Let Remote Users Crash the System
Categorie: Vulnerability Posted: 2004-01-09 by ReCall Views: 400 Source: Click here
Current Rating: Not rated
Details
Description: A denial of service vulnerability was reported in jabberd. A remote user can cause the target jabberd service to crash.
It is reported that the software does not properly handle SSL connections, as non-blocking sockets are not used. The flaw reportedly resides in 'mio_ssl.c'.
A remote user may be able to cause the target daemon to crash.
Impact: A remote user can cause the jabberd process to crash.
Solution: The vendor has released a fixed version (1.4.3), available at: