Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 372741 - <net-im/prosody-0.8.1: multiple vulnerabilites (CVE-2011-{2205,2531,2532})
Summary: <net-im/prosody-0.8.1: multiple vulnerabilites (CVE-2011-{2205,2531,2532})
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL:
Whiteboard: ~3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2011-06-24 00:42 UTC by GLSAMaker/CVETool Bot
Modified: 2011-06-26 21:21 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description GLSAMaker/CVETool Bot gentoo-dev 2011-06-24 00:42:14 UTC
CVE-2011-2531 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2531):
  Prosody 0.8.x before 0.8.1, when MySQL is used, assigns an incorrect data
  type to the value column in certain tables, which might allow remote
  attackers to cause a denial of service (data truncation) by sending a large
  amount of data.
Comment 1 Dirkjan Ochtman (RETIRED) gentoo-dev 2011-06-24 08:09:38 UTC
The ebuild for this is in the tree, we could just stabilize it.
Comment 2 GLSAMaker/CVETool Bot gentoo-dev 2011-06-25 12:15:40 UTC
CVE-2011-2532 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2532):
  The json.decode function in util/json.lua in Prosody 0.8.x before 0.8.1
  might allow remote attackers to cause a denial of service (infinite loop)
  via invalid JSON data, as demonstrated by truncated data.

CVE-2011-2205 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2205):
  Prosody before 0.8.1 does not properly detect recursion during entity
  expansion, which allows remote attackers to cause a denial of service
  (memory and CPU consumption) via a crafted XML document containing a large
  number of nested entity references, a similar issue to CVE-2003-1564.
Comment 3 Tim Sammut (RETIRED) gentoo-dev 2011-06-26 21:21:13 UTC
(In reply to comment #1)
> The ebuild for this is in the tree, we could just stabilize it.

Thank you; no stabilization is required.

Closing noglsa for ~arch only package.