This update for prosody fixes the following issues:
prosody was updated to 0.11.9:
Security:
* mod_limits, prosody.cfg.lua: Enable rate limits by default
* certmanager: Disable renegotiation by default
* mod_proxy65: Restrict access to local c2s connections by default
* util.startup: Set more aggressive defaults for GC
* mod_c2s, mod_s2s, mod_component, mod_bosh, mod_websockets: Set default
stanza size limits
* mod_authinternal{plain,hashed}: Use constant-time string comparison for
secrets
* mod_dialback: Remove dialback-without-dialback feature
* mod_dialback: Use constant-time comparison with hmac
Minor changes:
* util.hashes: Add constant-time string comparison (binding to
CRYPTO_memcmp)
* mod_c2s: Don???t throw errors in async code when connections are gone
* mod_c2s: Fix traceback in session close when conn is nil
* core.certmanager: Improve detection of LuaSec/OpenSSL capabilities
* mod_saslauth: Use a...
Read the Full AdvisoryPatch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Backports SLE-15-SP2:
zypper in -t patch openSUSE-2021-751=1
- openSUSE Backports SLE-15-SP2 (aarch64 ppc64le s390x x86_64):
prosody-0.11.9-bp152.2.3.1
https://www.suse.com/security/cve/CVE-2021-32917.html
https://www.suse.com/security/cve/CVE-2021-32918.html
https://www.suse.com/security/cve/CVE-2021-32919.html
https://www.suse.com/security/cve/CVE-2021-32920.html
https://bugzilla.suse.com/1186027
Get the latest Linux and open source security news straight to your inbox.