Back to search
CVE-2011-3288
Published: Oct 6, 2011
Modified: Sep 16, 2024
PUBLISHED
Description
Cisco Unified Presence before 8.5(4) does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption, and process crash) via a crafted XML document containing a large number of nested entity references, aka Bug IDs CSCtq89842 and CSCtq88547, a similar issue to CVE-2003-1564.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
20110928 Jabber Extensible Communications Platform and Cisco Unified Presence XML Denial of Service Vulnerability
vendor-advisory
x_refsource_CISCO
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now