Jabber Studio jabberd SASL Negotiation Remote DoS
Medium Nessus Plugin ID 21120
SynopsisThe remote instant messaging server is affected by a denial of service issue.
DescriptionThe remote host is running jabberd, an open source messaging system based on the Jabber protocol.
The version of jabberd installed on the remote host suffers a segfault when a client sends a SASL 'response' stanza before a SASL 'auth' stanza. An unauthenticated, remote attacker can leverage this flaw to crash the application's c2s component, thereby denying service to legitimate users.
SolutionUpgrade to jabberd 2s11 or later.