CVE-2016-1231: Path Traversal
Published Jan 12, 2016
·Updated
Directory traversal vulnerability in the HTTP file-serving module (modhttpfiles) in Prosody 0.9.x before 0.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) in an unspecified path.
Affected Software
13 affected components
Fedoraproject Fedora=22
Fedoraproject Fedora=23
Prosody prosody=0.9.0
Prosody prosody=0.9.1
Prosody prosody=0.9.2
Prosody prosody=0.9.3
Prosody prosody=0.9.4
Prosody prosody=0.9.5
Prosody prosody=0.9.6
Prosody prosody=0.9.7
Prosody prosody=0.9.8
Debian Debian Linux=7.0
Debian Debian Linux=8.0
Remediation
Patch Available
Event History
Jan 12, 2016
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-1231?
CVE-2016-1231 is considered a medium severity vulnerability due to its ability to allow remote attackers to read arbitrary files on the server.
2
How do I fix CVE-2016-1231?
To fix CVE-2016-1231, upgrade Prosody to version 0.9.9 or later to patch the directory traversal vulnerability.
3
Which versions of Prosody are affected by CVE-2016-1231?
CVE-2016-1231 affects Prosody versions 0.9.0 through 0.9.8.
4
What systems are vulnerable to CVE-2016-1231?
Vulnerable systems include specific versions of Fedora and Debian Linux that are running affected versions of Prosody.
5
Can CVE-2016-1231 be exploited remotely?
Yes, CVE-2016-1231 can be exploited remotely by attackers through the HTTP file-serving module.