Vulnerability Description
The SASL negotiation in Jabber Studio jabberd before 2.0s11 allows remote attackers to cause a denial of service ("c2s segfault") by sending a "response stanza before an auth stanza".
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Jabberstudio | Jabberd | <= 2.0_s10 |
References
- http://article.gmane.org/gmane.network.jabber.admin/27372Patch
- http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html
- http://secunia.com/advisories/19281Vendor Advisory
- http://support.apple.com/kb/HT4077
- http://www.redhat.com/support/errata/RHSA-2008-0261.html
- http://www.securityfocus.com/bid/17155
- http://www.vupen.com/english/advisories/2006/1009Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25334
- http://article.gmane.org/gmane.network.jabber.admin/27372Patch
- http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html
- http://secunia.com/advisories/19281Vendor Advisory
- http://support.apple.com/kb/HT4077
- http://www.redhat.com/support/errata/RHSA-2008-0261.html
- http://www.securityfocus.com/bid/17155
- http://www.vupen.com/english/advisories/2006/1009Vendor Advisory
FAQ
What is CVE-2006-1329?
CVE-2006-1329 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The SASL negotiation in Jabber Studio jabberd before 2.0s11 allows remote attackers to cause a denial of service ("c2s segfault") by sending a "response stanza before an auth stanza".
How severe is CVE-2006-1329?
CVE-2006-1329 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-1329?
Check the references section above for vendor advisories and patch information. Affected products include: Jabberstudio Jabberd.