{"id":"UBUNTU-CVE-2010-0305","details":"ejabberd_c2s.erl in ejabberd before 2.1.3 allows remote attackers to cause a denial of service (daemon crash) via a large number of c2s (aka client2server) messages that trigger a queue overload.","modified":"2025-07-16T07:30:39.289240Z","published":"2010-02-03T19:30:00Z","withdrawn":"2025-07-18T16:42:39Z","upstream":["CVE-2010-0305"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2010-0305"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2010-0305"}],"affected":[{"package":{"name":"ejabberd","ecosystem":"Ubuntu:14.04:LTS","purl":"pkg:deb/ubuntu/ejabberd@2.1.11-1ubuntu2.1?arch=source&distro=trusty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.1.11-1ubuntu2.1"}]}],"versions":["2.1.10-5ubuntu1","2.1.11-1","2.1.11-1ubuntu1","2.1.11-1ubuntu2"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"ejabberd","binary_version":"2.1.11-1ubuntu2.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2010/UBUNTU-CVE-2010-0305.json"}},{"package":{"name":"ejabberd","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/ejabberd@16.01-2?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"16.01-2"}]}],"versions":["15.03-2","15.10-3","16.01-1"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_version":"16.01-2","binary_name":"ejabberd"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2010/UBUNTU-CVE-2010-0305.json"}},{"package":{"name":"ejabberd","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/ejabberd@18.01-2?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"18.01-2"}]}],"versions":["17.07-1","17.08-3","17.11-1","18.01-1"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"ejabberd","binary_version":"18.01-2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2010/UBUNTU-CVE-2010-0305.json"}}],"schema_version":"1.7.3","severity":[{"type":"Ubuntu","score":"medium"}]}