Vulnerabilities > CVE-2004-0013 - Denial of Service vulnerability in Jabber Server SSL Handling

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
low complexity
jabber-software-foundation
nessus

Summary

jabber 1.4.2, 1.4.2a, and possibly earlier versions, does not properly handle SSL connections, which allows remote attackers to cause a denial of service (crash).

Nessus

  • NASL familyMandriva Local Security Checks
    NASL idMANDRAKE_MDKSA-2004-005.NASL
    descriptionA vulnerability was found in the jabber program where a bug in the handling of SSL connections could cause the server process to crash, resulting in a DoS (Denial of Service). The updated packages are patched to correct the problem.
    last seen2020-06-01
    modified2020-06-02
    plugin id14105
    published2004-07-31
    reporterThis script is Copyright (C) 2004-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/14105
    titleMandrake Linux Security Advisory : jabber (MDKSA-2004:005)
  • NASL familyDebian Local Security Checks
    NASL idDEBIAN_DSA-414.NASL
    descriptionA vulnerability was discovered in jabber, an instant messaging server, whereby a bug in the handling of SSL connections could cause the server process to crash, resulting in a denial of service.
    last seen2020-06-01
    modified2020-06-02
    plugin id15251
    published2004-09-29
    reporterThis script is Copyright (C) 2004-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/15251
    titleDebian DSA-414-1 : jabber - denial of service