PT-2011-3919 · Prosody · Prosody

Published

2011-06-22

·

Updated

2011-06-28

·

CVE-2011-2532

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Prosody versions 0.8.0 through 0.8.1
Description The issue is related to the json.decode function in util/json.lua, which might allow remote attackers to cause a denial of service (infinite loop) via invalid JSON data. This can be demonstrated by sending truncated data.
Recommendations For versions 0.8.0 through 0.8.1, update to version 0.8.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the json.decode function in util/json.lua to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-2532

Affected Products

Prosody