{
  "modified": "2025-08-09T19:01:26Z",
  "published": "2011-06-21T02:52:42Z",
  "id": "CVE-2011-1753",
  "details": "expat_erl.c in ejabberd before 2.1.7 and 3.x before 3.0.0-alpha-3, and exmpp before 0.9.7, does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.",
  "references": [
    {
      "type": "ADVISORY",
      "url": "http://secunia.com/advisories/44765"
    },
    {
      "type": "ADVISORY",
      "url": "http://secunia.com/advisories/44807"
    },
    {
      "type": "ADVISORY",
      "url": "http://secunia.com/advisories/45120"
    },
    {
      "type": "ADVISORY",
      "url": "http://www.debian.org/security/2011/dsa-2248"
    },
    {
      "type": "FIX",
      "url": "http://www.ejabberd.im/ejabberd-2.1.7"
    },
    {
      "type": "FIX",
      "url": "https://git.process-one.net/ejabberd/mainline/commit/bd1df027c622e1f96f9eeaac612a6a956c1ff0b6"
    },
    {
      "type": "REPORT",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=700454"
    },
    {
      "type": "WEB",
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2011-June/062099.html"
    },
    {
      "type": "WEB",
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2011-June/062145.html"
    },
    {
      "type": "WEB",
      "url": "http://www.process-one.net/en/ejabberd/release_notes/release_note_ejabberd_2.1.7/"
    },
    {
      "type": "WEB",
      "url": "http://www.securityfocus.com/bid/48072"
    },
    {
      "type": "WEB",
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/67769"
    }
  ]
}
