PT-2014-8715 · Processone+1 · Ejabberd+1

Weiss

·

Publicado

2014-10-23

·

Atualizado

2016-04-11

·

CVE-2014-8760

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions ejabberd versions prior to 2.1.13
Description The issue causes clients to establish connections without encryption when compression is used, due to the failure to enforce the starttls required setting.
Recommendations For versions prior to 2.1.13, update to version 2.1.13 or later to resolve the issue. As a temporary workaround, consider disabling compression until a patch is available. Restrict access to unencrypted connections to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2016-1317
CVE-2014-8760
DLA-881-1
MGASA-2014-0417

Produtos afetados

Alt Linux
Ejabberd