First published: Thu Sep 14 2017(Updated: )
Prosody before 0.10.0 allows remote attackers to cause a denial of service (application crash), related to an incompatibility with certain versions of the LuaSocket library, such as the lua-socket package from Debian stretch. The attacker needs to trigger a stream error. A crash can be observed in, for example, the c2s module.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/prosody | 0.11.2-1+deb10u4 0.11.9-2+deb11u2 0.12.3-1 0.12.4-1 | |
Prosody | <0.10.0 | |
Debian | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-18265 has a severity rating that indicates a denial of service vulnerability in Prosody before version 0.10.0.
To fix CVE-2017-18265, upgrade Prosody to version 0.11.2-1+deb10u4 or later.
CVE-2017-18265 affects Prosody versions prior to 0.10.0, as well as certain versions of the LuaSocket library.
Yes, CVE-2017-18265 can be exploited remotely by triggering a stream error.
The potential impact of CVE-2017-18265 is an application crash, leading to a denial of service.