Search:     Advanced search
server monitoring

Openfire < 3.5.0 ConnectionManagerImpl.java Queue Handling Remote DoS

Article ID: 31855
Last updated: 27 Jan, 2009
Views: 425
Posted: 22 Jan, 2009
by: Tech Pubs S.
Updated: 27 Jan, 2009
by: Tech Pubs S.

Openfire < 3.5.0 ConnectionManagerImpl.java Queue Handling Remote DoS

This script is Copyright (C) 2007-2008 Tenable Network Security, Inc.

FamilyDenial of Service
Plugin ID31855
Bugtraq ID28722
CVE IDCVE-2008-1728

Description:

Synopsis :

The remote host contains an application that is prone to a denial of
service attack.

Description :

The remote host is running Openfire / Wildfire, an instant messaging
server supporting the XMPP protocol.

According to its version, the installation of Openfire or Wildfire on
the remote host suffers from a denial of service vulnerability that
could bring the server down because it has no limit on a client
sessions send buffer and can not handle clients that fail to read
messages.

See also :

http://www.igniterealtime.org/issues/browse/JM-1289
http://www.openwall.com/lists/oss-security/2008/04/10/7

Solution :

Upgrade to Openfire version 3.5.0 or later.

Risk factor :

High / CVSS Base Score : 7.8
(CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C)
This article was:   Helpful | Not Helpful
Prev   Next
Too long basic authentication DoS     TCP/IP Ping of Death Remote DoS