CVE-2016-1232: High severity prosody vulnerability
Published Jan 12, 2016
·Updated
The moddialback module in Prosody before 0.9.9 does not properly generate random values for the secret token for server-to-server dialback authentication, which makes it easier for attackers to spoof servers via a brute force attack.
Affected Software
13 affected components
Prosody prosody<=0.9.8
Prosody prosody=0.9.0
Prosody prosody=0.9.1
Prosody prosody=0.9.2
Prosody prosody=0.9.3
Prosody prosody=0.9.4
Prosody prosody=0.9.5
Prosody prosody=0.9.6
Prosody prosody=0.9.7
Fedoraproject Fedora=22
Fedoraproject Fedora=23
Debian Debian Linux=7.0
Debian Debian Linux=8.0
Remediation
Patch Available
Event History
Jan 12, 2016
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-1232?
CVE-2016-1232 has a moderate severity rating due to its potential to allow brute force attacks that can spoof servers.
2
How do I fix CVE-2016-1232?
To fix CVE-2016-1232, upgrade Prosody to version 0.9.9 or later, as this version addresses the vulnerability.
3
Which versions of Prosody are affected by CVE-2016-1232?
CVE-2016-1232 affects Prosody versions 0.9.0 to 0.9.8.
4
What components of Prosody are impacted by CVE-2016-1232?
The mod_dialback module in Prosody is specifically impacted by CVE-2016-1232.
5
Can CVE-2016-1232 lead to unauthorized server communications?
Yes, CVE-2016-1232 can facilitate unauthorized server communications by enabling attackers to spoof server identities.