SB2014042407 - Permissions, Privileges, and Access Controls in prosody (Alpine package)
Published: April 24, 2014
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2014-2745)
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
Prosody before 0.9.4 does not properly restrict the processing of compressed XML elements, which allows remote attackers to cause a denial of service (resource consumption) via a crafted XMPP stream, aka an "xmppbomb" attack, related to core/portmanager.lua and util/xmppstream.lua.
Remediation
Install update from vendor's website.