CVE : CVE-2018-10847 Date : 2018-05-31 Affected versions : 0.9.x prior to 0.9.14, 0.10.x prior to 0.10.2. All prior series affected. Fixed versions : 0.9.14, 0.10.2 Description ----------- Due to insufficient validation of client-provided parameters during XMPP stream restarts, authenticated users may override the realm associated with their session, potentially bypassing security policies and allowing impersonation.
prosody-0.10.2.ebuild and prosody-0.9.14.ebuild are in the tree, adding arches. Arches, please test and mark stable: =net-im/prosody-0.9.14
amd64 stable
x86 stable
arm stable, all arches done.
@maintainer(s), please clean vulnerable.
(In reply to Aaron Bauman from comment #5) > @maintainer(s), please clean vulnerable. Done.
(In reply to Tobias Klausmann from comment #6) > (In reply to Aaron Bauman from comment #5) > > @maintainer(s), please clean vulnerable. > > Done. Fastest cleanup ever! Thanks, Tobias.