Summary
The remote host is missing updates announced in
advisory GLSA 200409-31.
Solution
All jabberd users should upgrade to the latest version:
# emerge sync
# emerge -pv '>=net-im/jabberd-1.4.3-r4'
# emerge '>=net-im/jabberd-1.4.3-r4'
http://www.securityspace.com/smysecure/catid.html?in=GLSA%20200409-31 http://bugs.gentoo.org/show_bug.cgi?id=64741
http://www.jabber.org/pipermail/jabberd/2004-September/002004.html http://www.jabber.org/pipermail/jadmin/2004-September/018046.html
Insight
The jabberd server was found to be vulnerable to a remote Denial of Service attack.
Severity
Classification
-
CVE CVE-2004-1378 -
CVSS Base Score: 5.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
Related Vulnerabilities