Alerts This Week
Warning Icon 1 684
Alerts This Week
Warning Icon 1 684

Debian: DSA-4216-1 Severe: Prosody Session Threat Update

debian
Calendar Grey June 2, 2018
Debian Logo
Ubuntu Security Notice USN-4625-1 highlights an essential OpenSSL update fixing critical buffer overflow issues in version handling
It was discovered that Prosody, a lightweight Jabber/XMPP server, does not properly validate client-provided parameters during XMPP stream restarts, allowing authenticated users to...

Summary

Details can be found in the upstream advisory at
https://prosody.im/security/advisory_20180531/

For the oldstable distribution (jessie), this problem has been fixed
in version 0.9.7-2+deb8u4.

For the stable distribution (stretch), this problem has been fixed in
version 0.9.12-2+deb9u2.

We recommend that you upgrade your prosody packages.

For the detailed security status of prosody please refer to its security
tracker page at:
https://security-tracker.debian.org/tracker/source-package/prosody

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: prosody
CVE ID: CVE-2018-10847

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here