VYPR
Unrated severityNVD Advisory· Published Jun 21, 2011· Updated Apr 29, 2026

CVE-2011-1756

CVE-2011-1756

Description

modules/xmpp/serv_xmpp.c in Citadel 7.86 and earlier does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.

Affected products

8
  • Citadel/Citadel8 versions
    cpe:2.3:a:citadel:citadel:*:*:*:*:*:*:*:*+ 7 more
    • cpe:2.3:a:citadel:citadel:*:*:*:*:*:*:*:*range: <=7.86
    • cpe:2.3:a:citadel:citadel:7.11:*:*:*:*:*:*:*
    • cpe:2.3:a:citadel:citadel:7.50:*:*:*:*:*:*:*
    • cpe:2.3:a:citadel:citadel:7.60:*:*:*:*:*:*:*
    • cpe:2.3:a:citadel:citadel:7.80:*:*:*:*:*:*:*
    • cpe:2.3:a:citadel:citadel:7.81:*:*:*:*:*:*:*
    • cpe:2.3:a:citadel:citadel:7.82:*:*:*:*:*:*:*
    • cpe:2.3:a:citadel:citadel:7.84:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

8

News mentions

0

No linked articles in our index yet.