Logo
componentprosody
Name
prosody
Version
0.11.14
Type
library
Description
-
Licenses
MIT
PURL
-
CPE
cpe:2.3:a:prosody:prosody:0.11.14:-:*:*:*:*:*:*

Other Versions#


Project
Branch
Version
master
0.11.14

Patches#


#
Title
Author
Resolve
1
enable syslog
Francois Perrad <francois.perrad@gadz.org>
2
add pidfile
Francois Perrad <francois.perrad@gadz.org>

Vulnerabilities#


Name
Analysis
Description
Exploitable
An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5. A Denial of Service can occur via memory exhaustion caused by XML parsing resource amplification from unauthenticated connections.
Exploitable
An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5. A Denial of Service can occur via memory exhaustion caused by memory leaks from unauthenticated connections.
Exploitable
An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5, when mod_proxy65 is enabled. Because mod_proxy65 mishandles access control in the activation scenario, relaying of unauthenticated traffic can occur.
Exploitable
An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5, when mod_proxy65 is enabled. Because mod_proxy65 mishandles access control in a paused scenario, relaying of unauthenticated traffic can occur.