Resource exhaustion in Prosody - CVE-2021-32918

 

Resource exhaustion in Prosody - CVE-2021-32918

Published: May 17, 2021


Vulnerability identifier: #VU53316
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-32918
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources. A remote attacker can perform a denial of service (DoS) attack ia memory exhaustion when running under Lua 5.2 or Lua 5.3.


Affected software

Prosody
Gentoo Linux
Arch Linux
Fedora
prosody (Debian package)
prosody

How to mitigate CVE-2021-32918

Install updates from vendor's website.

Prosody - update to 0.11.9
prosody (Debian package) - update to 0.11.2-1+deb10u1
prosody - addressed in versions 0.11.9-1.el7, 0.11.9-1.el8, 0.11.9-1.fc32, 0.11.9-1.fc33, 0.11.9-1.fc34

External References

Related Security Bulletins