PT-2016-4403 · Prosody · Prosody
Thijs Alkemade
·
Published
2016-01-29
·
Updated
2024-06-15
·
CVE-2016-0756
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Prosody versions prior to 0.9.10
Description
The issue arises from the
generate dialback function in the mod dialback module, which fails to properly separate fields when generating dialback keys. This allows remote attackers to spoof XMPP network domains by crafting a stream id and domain name that is included in the target domain as a suffix.Recommendations
For versions prior to 0.9.10, update to version 0.9.10 or later to resolve the issue. As a temporary workaround, consider restricting access to the
mod dialback module to minimize the risk of exploitation.Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Prosody