Bug 1092882 (CVE-2017-18265) - VUL-0: CVE-2017-18265: prosody: denial of service related to an incompatibility with certain versions of the LuaSocket library
Summary: VUL-0: CVE-2017-18265: prosody: denial of service related to an incompatibili...
Status: RESOLVED FIXED
Alias: CVE-2017-18265
Product: openSUSE Distribution
Classification: openSUSE
Component: Security (show other bugs)
Version: Leap 42.3
Hardware: Other Other
: P3 - Medium : Normal (vote)
Target Milestone: ---
Assignee: Alexander Bergmann
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/205473/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2018-05-11 07:57 UTC by Alexander Bergmann
Modified: 2019-07-11 15:08 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexander Bergmann 2018-05-11 07:57:21 UTC
CVE-2017-18265

Prosody before 0.10.0 allows remote attackers to cause a denial of service
(application crash), related to an incompatibility with certain versions of the
LuaSocket library, such as the lua-socket package from Debian stretch. The
attacker needs to trigger a stream error. A crash can be observed in, for
example, the c2s module.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-18265
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=875829
http://www.debian.org/security/2018/dsa-4198
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-18265
https://hg.prosody.im/0.9/rev/176b7f4e4ac9
https://prosody.im/issues/issue/987
https://hg.prosody.im/0.9/rev/adfffc5b4e2a
Comment 1 Alexander Bergmann 2018-05-11 07:58:12 UTC
Mathias, Michael, could you please have a look?
Comment 2 Mathias Homann 2018-05-11 10:09:08 UTC
i can't open the link to the description... what IS this "smash.suse.de" host?
Comment 3 Michael Vetter 2018-05-14 09:45:11 UTC
Sorry, only saw this now.

Created https://bugzilla.suse.com/show_bug.cgi?id=1093088 this morning.

Update to prosody 0.9.13 should solve this.
Comment 4 Michael Vetter 2018-05-14 10:37:28 UTC
SR#606983 got accepted.

Alexander, please decide whether this can be closed.
Comment 5 Tomáš Chvátal 2019-07-11 11:30:14 UTC
This is automated batch bugzilla cleanup.

The openSUSE 42.3 changed to end-of-life (EOL [1]) status. As such
it is no longer maintained, which means that it will not receive any
further security or bug fix updates.
As a result we are closing this bug.

If you can reproduce this bug against a currently maintained version of 
openSUSE (At this moment openSUSE Leap 15.1, 15.0 and Tumbleweed) please
feel free to reopen this bug against that version (!you must update the
"Version" component in the bug fields, do not just reopen please), or
alternatively create a new ticket.

Thank you for reporting this bug and we are sorry it could not be fixed
during the lifetime of the release.

[1] https://en.opensuse.org/Lifetime
Comment 6 Marcus Meissner 2019-07-11 15:08:50 UTC
15.0 has 0.10.1 -> fixed