Alerts This Week
Warning Icon 1 609
Alerts This Week
Warning Icon 1 609

Debian: DSA-3439-1 Critical: Prosody Remote Access and Auth Flaws

debian
Calendar Grey January 10, 2016
Debian Logo
Debian Security Advisory DSA-3440-1 outlines significant security updates addressing vulnerabilities in OpenSSL related to data encryption and integrity protocols.
Two vulnerabilities were discovered in Prosody, a lightweight Jabber/XMPP server

Summary

CVE-2016-1231

Kim Alvefur discovered a flaw in Prosody's HTTP file-serving module
that allows it to serve requests outside of the configured public
root directory. A remote attacker can exploit this flaw to access
private files including sensitive data. The default configuration
does not enable the mod_http_files module and thus is not
vulnerable.

CVE-2016-1232

Thijs Alkemade discovered that Prosody's generation of the secret
token for server-to-server dialback authentication relied upon a
weak random number generator that was not cryptographically secure.
A remote attacker can take advantage of this flaw to guess at
probable values of the secret key and impersonate the affected
domain to other servers on the network.

For the oldstable distribution (wheezy), these problems have been fixed
in version 0.8.2-4+deb7u3.

For the stable distribution (jessie), these problems have been fixed in
version 0.9.7-2+deb8u2.

We recommend that you upgrade your prosody p...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: prosody
CVE ID: CVE-2016-1231 CVE-2016-1232

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here