Unrated severityNVD Advisory· Published Apr 11, 2014· Updated May 6, 2026
CVE-2014-2744
CVE-2014-2744
Description
plugins/mod_compression.lua in (1) Prosody before 0.9.4 and (2) Lightwitch Metronome through 3.4 negotiates stream compression while a session is unauthenticated, which allows remote attackers to cause a denial of service (resource consumption) via compressed XML elements in an XMPP stream, aka an "xmppbomb" attack.
Affected products
21cpe:2.3:a:prosody:prosody:*:*:*:*:*:*:*:*+ 19 more
- cpe:2.3:a:prosody:prosody:*:*:*:*:*:*:*:*range: <=0.9.3
- cpe:2.3:a:prosody:prosody:0.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:prosody:prosody:0.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:prosody:prosody:0.3.0:*:*:*:*:*:*:*
- cpe:2.3:a:prosody:prosody:0.4.0:*:*:*:*:*:*:*
- cpe:2.3:a:prosody:prosody:0.4.1:*:*:*:*:*:*:*
- cpe:2.3:a:prosody:prosody:0.4.2:*:*:*:*:*:*:*
- cpe:2.3:a:prosody:prosody:0.5.0:*:*:*:*:*:*:*
- cpe:2.3:a:prosody:prosody:0.5.1:*:*:*:*:*:*:*
- cpe:2.3:a:prosody:prosody:0.5.2:*:*:*:*:*:*:*
- cpe:2.3:a:prosody:prosody:0.6.0:*:*:*:*:*:*:*
- cpe:2.3:a:prosody:prosody:0.6.1:*:*:*:*:*:*:*
- cpe:2.3:a:prosody:prosody:0.6.2:*:*:*:*:*:*:*
- cpe:2.3:a:prosody:prosody:0.7.0:*:*:*:*:*:*:*
- cpe:2.3:a:prosody:prosody:0.8.0:*:*:*:*:*:*:*
- cpe:2.3:a:prosody:prosody:0.8.1:*:*:*:*:*:*:*
- cpe:2.3:a:prosody:prosody:0.8.2:*:*:*:*:*:*:*
- cpe:2.3:a:prosody:prosody:0.9.0:*:*:*:*:*:*:*
- cpe:2.3:a:prosody:prosody:0.9.1:*:*:*:*:*:*:*
- cpe:2.3:a:prosody:prosody:0.9.2:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- code.lightwitch.org/metronome/rev/49f47277a411nvdExploitPatch
- hg.prosody.im/0.9/rev/b3b1c9da38fbnvdExploitPatch
- blog.prosody.im/prosody-0-9-4-released/nvdVendor Advisory
- openwall.com/lists/oss-security/2014/04/07/7nvd
- openwall.com/lists/oss-security/2014/04/09/1nvd
- secunia.com/advisories/57710nvd
- www.debian.org/security/2014/dsa-2895nvd
- xmpp.org/resources/security-notices/uncontrolled-resource-consumption-with-highly-compressed-xmpp-stanzas/nvd
News mentions
0No linked articles in our index yet.