CVE-2017-18265: High severity prosody vulnerability
Prosody before 0.10.0 allows remote attackers to cause a denial of service (application crash), related to an incompatibility with certain versions of the LuaSocket library, such as the lua-socket package from Debian stretch. The attacker needs to trigger a stream error. A crash can be observed in, for example, the c2s module.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-18265?
CVE-2017-18265 has a severity rating that indicates a denial of service vulnerability in Prosody before version 0.10.0.
How do I fix CVE-2017-18265?
To fix CVE-2017-18265, upgrade Prosody to version 0.11.2-1+deb10u4 or later.
What software is affected by CVE-2017-18265?
CVE-2017-18265 affects Prosody versions prior to 0.10.0, as well as certain versions of the LuaSocket library.
Can CVE-2017-18265 be exploited remotely?
Yes, CVE-2017-18265 can be exploited remotely by triggering a stream error.
What is the potential impact of CVE-2017-18265?
The potential impact of CVE-2017-18265 is an application crash, leading to a denial of service.