PT-2011-3919 · Prosody · Prosody

Publicado

2011-06-22

·

Atualizado

2011-06-28

·

CVE-2011-2532

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Prosody versions 0.8.0 through 0.8.1
Description The issue is related to the json.decode function in util/json.lua, which might allow remote attackers to cause a denial of service (infinite loop) via invalid JSON data. This can be demonstrated by sending truncated data.
Recommendations For versions 0.8.0 through 0.8.1, update to version 0.8.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the json.decode function in util/json.lua to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-2532

Produtos afetados

Prosody