Unrated severityNVD Advisory· Published Apr 11, 2014· Updated May 6, 2026
CVE-2014-2745
CVE-2014-2745
Description
Prosody before 0.9.4 does not properly restrict the processing of compressed XML elements, which allows remote attackers to cause a denial of service (resource consumption) via a crafted XMPP stream, aka an "xmppbomb" attack, related to core/portmanager.lua and util/xmppstream.lua.
Affected products
20cpe:2.3:a:prosody:prosody:*:*:*:*:*:*:*:*+ 19 more
- cpe:2.3:a:prosody:prosody:*:*:*:*:*:*:*:*range: <=0.9.3
- cpe:2.3:a:prosody:prosody:0.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:prosody:prosody:0.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:prosody:prosody:0.3.0:*:*:*:*:*:*:*
- cpe:2.3:a:prosody:prosody:0.4.0:*:*:*:*:*:*:*
- cpe:2.3:a:prosody:prosody:0.4.1:*:*:*:*:*:*:*
- cpe:2.3:a:prosody:prosody:0.4.2:*:*:*:*:*:*:*
- cpe:2.3:a:prosody:prosody:0.5.0:*:*:*:*:*:*:*
- cpe:2.3:a:prosody:prosody:0.5.1:*:*:*:*:*:*:*
- cpe:2.3:a:prosody:prosody:0.5.2:*:*:*:*:*:*:*
- cpe:2.3:a:prosody:prosody:0.6.0:*:*:*:*:*:*:*
- cpe:2.3:a:prosody:prosody:0.6.1:*:*:*:*:*:*:*
- cpe:2.3:a:prosody:prosody:0.6.2:*:*:*:*:*:*:*
- cpe:2.3:a:prosody:prosody:0.7.0:*:*:*:*:*:*:*
- cpe:2.3:a:prosody:prosody:0.8.0:*:*:*:*:*:*:*
- cpe:2.3:a:prosody:prosody:0.8.1:*:*:*:*:*:*:*
- cpe:2.3:a:prosody:prosody:0.8.2:*:*:*:*:*:*:*
- cpe:2.3:a:prosody:prosody:0.9.0:*:*:*:*:*:*:*
- cpe:2.3:a:prosody:prosody:0.9.1:*:*:*:*:*:*:*
- cpe:2.3:a:prosody:prosody:0.9.2:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- blog.prosody.im/prosody-0-9-4-released/nvd
- hg.prosody.im/0.9/rev/1107d66d2ab2nvd
- hg.prosody.im/0.9/rev/a97591d2e1adnvd
- openwall.com/lists/oss-security/2014/04/07/7nvd
- openwall.com/lists/oss-security/2014/04/09/1nvd
- secunia.com/advisories/57710nvd
- www.debian.org/security/2014/dsa-2895nvd
- xmpp.org/resources/security-notices/uncontrolled-resource-consumption-with-highly-compressed-xmpp-stanzas/nvd
News mentions
0No linked articles in our index yet.