First published: Thu Sep 14 2017(Updated: )
Prosody before 0.10.0 allows remote attackers to cause a denial of service (application crash), related to an incompatibility with certain versions of the LuaSocket library, such as the lua-socket package from Debian stretch. The attacker needs to trigger a stream error. A crash can be observed in, for example, the c2s module.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Prosody Prosody | <0.10.0 | |
Debian Debian Linux | =9.0 | |
debian/prosody | 0.11.2-1+deb10u4 0.11.9-2+deb11u2 0.12.3-1 0.12.4-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.