[jdev] Fwd: [Security] billion laughs attack
stpeter at stpeter.im
Wed Jun 1 17:59:30 UTC 2011
-------- Original Message --------
Subject: [Security] billion laughs attack
Date: Wed, 01 Jun 2011 11:58:13 -0600
From: Peter Saint-Andre <stpeter at stpeter.im>
Reply-To: XMPP Security <security at xmpp.org>
To: XMPP Security <security at xmpp.org>
Over the last few days, the Debian security team has announced fixes to
several XMPP server daemons to address the so-called "billion laughs"
This attack is not limited to those server daemons, and in fact applies
more generally to any XML-based applications. Other XMPP software
projects (servers, clients, and libraries) might also vulnerable, and
developers are encouraged to review their code.
Background information can be found at the following web pages:
-------------- next part --------------
A non-text attachment was scrubbed...
Size: 6105 bytes
Desc: S/MIME Cryptographic Signature
More information about the JDev