modules/xmpp/serv_xmpp.c in Citadel 7.86 and earlier does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "citadel-dbg",
"binary_version": "8.24-1"
},
{
"binary_name": "citadel-doc",
"binary_version": "8.24-1"
},
{
"binary_name": "citadel-mta",
"binary_version": "8.24-1"
},
{
"binary_name": "citadel-server",
"binary_version": "8.24-1"
}
]
}