GHSA-5v5w-44w6-q5hv
Dashboard / Vulnerabilities / GHSA-5v5w-44w6-q5hv
Summary: Erlang Solutions MongooseIM vulnerable to denial of service (DoS) via crafted XMPP stream
Details: Erlang Solutions MongooseIM through 1.3.1 rev. 2 does not properly restrict the processing of compressed XML elements, which allows remote attackers to cause a denial of service (resource consumption) via a crafted XMPP stream, aka an "xmppbomb" attack.
References: https://nvd.nist.gov/vuln/detail/CVE-2014-2829, https://github.com/esl/MongooseIM/commit/586d96cc12ef218243a3466354b4d208b5472a6c, https://github.com/esl/MongooseIM, http://xmpp.org/resources/security-notices/uncontrolled-resource-consumption-with-highly-compressed-xmpp-stanzas
Affected packages
Package
Name: MongooseIM
Purl: pkg:hex/MongooseIM
Affected ranges
Type: SEMVER
Events:
