[prev in list] [next in list] [prev in thread] [next in thread] 

List:       jabber-jdev
Subject:    [jdev] Fwd: [Security] Security Notice: Uncontrolled Resource Consumption with Highly-Compressed XMP
From:       Peter Saint-Andre <stpeter () stpeter ! im>
Date:       2014-04-04 14:45:37
Message-ID: 533EC591.60309 () stpeter ! im
[Download RAW message or body]

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

FYI.


- -------- Original Message --------
Subject: [Security] Security Notice: Uncontrolled Resource Consumption
with Highly-Compressed XMPP Stanzas
Date: Fri, 04 Apr 2014 08:27:34 -0600
From: Peter Saint-Andre <stpeter@stpeter.im>
Reply-To: XMPP Security <security@xmpp.org>
To: security@xmpp.org

The XMPP Standards Foundation has published a security notice
describing an uncontrolled resource consumption vulnerability in
several XMPP server implementations that support application-layer
compression. Details can be found at:

http://xmpp.org/resources/security-notices/uncontrolled-resource-consumption-with-highly-compressed-xmpp-stanzas/


Peter
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)
Comment: GPGTools - http://gpgtools.org
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQIcBAEBAgAGBQJTPsWRAAoJEOoGpJErxa2p22kP/1RLcbVSJ84VUzsUadMc3N2K
sqFNe4utZhINd3uZiXoi4I6lJIeq3c0QxLnzTnLd55EVptmvzbYTVfiXnDdroFdN
rtTJuidqBDE6Zihpo+IbU96aZz0nIQ2vgh/Lr05PelYS3n4ZTetA0u16XA5jyr/d
+daHR+tDARUcnAfawSWmelClsRC4ZGI8iQSLxsW4aAR4TRrQnLrc6I/gZzfQ0h/Q
zQFfrCFeEUmspcXJyb4C0IfJ+amd6WvjNxPZLTASsVydH1oSlgS8OrZxXwkyspRh
oR5ntItu+Emw1407B7ocA7Kl9eAimblY6/r6LK8xK2kcBb2D9d5S47ZvJGd/1kyS
S1SAedfUOvOQCx9USwtyo7F4CGdu551FImjVA73OIbkkJ6EiWpXHwxhVDEwr74sb
yG+fAjPZZgNrKewFWhKkfgcsaaMWCaMd5wzOI8s8i42e+/ujHYf4hlX6iU8/eSjj
SUjVbErPedSkUQOboqpACSmKGqNJcMRXFbTbDT8oVVpbcnrKhFuMuoqJVFLpJLRn
s0NReQb1CMfAXfVnna0RxF6tIqXe6xRCHdQSBVf+kP+ojN/W/kTSt/v7vvJzAV8Q
EHZ+9fNa6m4wtC/2+LrtHi4pbtqnOUFkF4I8B8DP3V4iAN/zeC0szcw3oUWQm3Nu
1ugN7i/WZS8NU1P3gVk8
=p1ob
-----END PGP SIGNATURE-----
_______________________________________________
JDev mailing list
Info: http://mail.jabber.org/mailman/listinfo/jdev
Unsubscribe: JDev-unsubscribe@jabber.org
_______________________________________________


[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic