Skip to content
This repository has been archived by the owner on Feb 12, 2019. It is now read-only.

jabberd 2.2.14

Compare
Choose a tag to compare
@smokku smokku released this 28 Nov 11:42
· 372 commits to master since this release

This is a security release dealing with “billion laughs” attack
possibility discovered in many XMPP servers. CVE-2011-1755

  • Prevent the “billion laughs” attack against expat by disabling
    internal entity expansion.
  • Shortcut DNS resolution failure in cases when given domain name
    is invalid
  • Explicitly link libcrypt to authreg_mysql
  • Removed xconfig - it's not used anywhere
  • Added Upstart service configuration files