PT-2021-4055 · Prosody+4 · Prosody+4

Moparisthebest

+1

·

Published

2021-05-02

·

Updated

2024-12-08

·

CVE-2021-32918

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Prosody versions prior to 0.11.9
Description An issue in Prosody allows remote unauthenticated denial-of-service (DoS) attacks via memory exhaustion when running under Lua 5.2 or Lua 5.3. The problem is related to an error in the resource control mechanism, which can be exploited by a remote attacker to cause a denial of service.
Recommendations For versions prior to 0.11.9, update to version 0.11.9 or later to resolve the issue. As a temporary workaround, consider restricting default settings to prevent memory exhaustion until a patch is applied.

Fix

DoS

Resource Exhaustion

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1808
ALT-PU-2021-2611
ALT-PU-2024-16554
BDU:2021-04583
CVE-2021-32918
DSA-4916-1
DSA-4916-2
OPENSUSE-SU-2021:0728-1
OPENSUSE-SU-2021:0751-1
OPENSUSE-SU-2021_0728-1
OPENSUSE-SU-2024:11197-1

Affected Products

Alt Linux
Lua 5.2
Lua 5.3
Prosody
Suse