Depth counting error in guard() leading to multiple potential security issues in aioxmpp
Description
Published by the National Vulnerability Database
Feb 4, 2019
Reviewed
Apr 29, 2020
Published to the GitHub Advisory Database
Apr 29, 2020
Last updated
Sep 4, 2024
Impact
Possible remote Denial of Service or Data Injection.
Patches
Patches are available in horazont/aioxmpp#268. They have been backported to the 0.10 release series and 0.10.3 is the first release to contain the fix.
Workarounds
To make the bug exploitable, an error suppressing
xso_error_handler
is required. By not usingxso_error_handlers
or not using the suppression function, the vulnerability can be mitigated completely (to our knowledge).References
The pull request contains a detailed description: horazont/aioxmpp#268
For more information
If you have any questions or comments about this advisory:
References