CVE-2006-1329

UnknownEPSS 2.83%

Last modified

CVE-2006-1329 is a vulnerability of currently unknown severity. The SASL negotiation in Jabber Studio jabberd before 2.0s11 allows remote attackers to cause a denial of service ("c2s segfault") by sending a "response stanza before an auth stanza".. EPSS estimates a 2.83% chance of exploitation in the next 30 days.

Description

The SASL negotiation in Jabber Studio jabberd before 2.0s11 allows remote attackers to cause a denial of service ("c2s segfault") by sending a "response stanza before an auth stanza".

Metrics

EPSS Probability
2.83%

84.8th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
JabberstudioJabberd<= 2.0_s10
JabberstudioJabberd2.0_a1
JabberstudioJabberd2.0_a2
JabberstudioJabberd2.0_a3
JabberstudioJabberd2.0_a4
JabberstudioJabberd2.0_a5
JabberstudioJabberd2.0_a6
JabberstudioJabberd2.0_b1
JabberstudioJabberd2.0_b2
JabberstudioJabberd2.0_b3
JabberstudioJabberd2.0_rc1
JabberstudioJabberd2.0_rc2
JabberstudioJabberd2.0_s1
JabberstudioJabberd2.0_s2
JabberstudioJabberd2.0_s3
JabberstudioJabberd2.0_s4
JabberstudioJabberd2.0_s5
JabberstudioJabberd2.0_s6
JabberstudioJabberd2.0_s7
JabberstudioJabberd2.0_s8
JabberstudioJabberd2.0_s9

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2006-1329?
The SASL negotiation in Jabber Studio jabberd before 2.0s11 allows remote attackers to cause a denial of service ("c2s segfault") by sending a "response stanza before an auth stanza".
How severe is CVE-2006-1329?
Severity scoring for CVE-2006-1329 is pending analysis. The EPSS model estimates a 2.83% probability of exploitation in the next 30 days.
How do I fix CVE-2006-1329?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2006-1329?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST