FreshPorts - VuXML

This page displays vulnerability information about FreeBSD Ports.

The VUXML data was last processed by FreshPorts on 2024-03-27 18:04:16 UTC

List all Vulnerabilities, by package

List all Vulnerabilities, by date

k68

These are the vulnerabilities relating to the commit you have selected:

VuXML IDDescription
50394bc9-c5fa-11e5-96a5-d93b343d1ff7prosody -- user impersonation vulnerability

The Prosody team reports:

Adopt key generation algorithm from XEP-0185, to prevent impersonation attacks (CVE-2016-0756)


Discovery 2016-01-27
Entry 2016-01-28
prosody
< 0.9.10

ports/206707
CVE-2016-0756
https://prosody.im/security/advisory_20160127/
fc75570a-b417-11eb-a23d-c7ab331fd711Prosody -- multiple vulnerabilities

The Prosody security advisory 2021-05-12 reports:

This advisory details 5 new security vulnerabilities discovered in the Prosody.im XMPP server software. All issues are fixed in the 0.11.9 release default configuration.

  • CVE-2021-32918: DoS via insufficient memory consumption controls
  • CVE-2021-32920: DoS via repeated TLS renegotiation causing excessive CPU consumption
  • CVE-2021-32921: Use of timing-dependent string comparison with sensitive values
  • CVE-2021-32917: Use of mod_proxy65 is unrestricted in default configuration
  • CVE-2021-32919: Undocumented dialback-without-dialback option insecure

Discovery 2021-05-12
Entry 2021-05-13
prosody
< 0.11.9

CVE-2021-32918
CVE-2021-32920
CVE-2021-32921
CVE-2021-32917
CVE-2021-32919
e3ec8b30-757b-11ec-922f-654747404482Prosody XMPP server advisory 2022-01-13

The Prosody teaM reports:

It was discovered that an internal Prosody library to load XML based on does not properly restrict the XML features allowed in parsed XML data. Given suitable attacker input, this results in expansion of recursive entity references from DTDs (CWE-776). In addition, depending on the libexpat version used, it may also allow injections using XML External Entity References (CWE-611).


Discovery 2022-01-10
Entry 2022-01-14
prosody
< 0.11.12

CVE-2022-0217
https://prosody.im/security/advisory_20220113/
5ef14250-f47c-11eb-8f13-5b4de959822eProsody -- Remote Information Disclosure

A Prosody XMPP server advisory reports:

It was discovered that Prosody allows any entity to access the list of admins, members, owners and banned entities of any federated XMPP group chat of which they know the address.


Discovery 2021-07-22
Entry 2021-08-03
prosody
< 0.11.10

CVE-2021-37601
https://prosody.im/security/advisory_20210722/
842cd117-ba54-11e5-9728-002590263bf5prosody -- multiple vulnerabilities

The Prosody Team reports:

Fix path traversal vulnerability in mod_http_files (CVE-2016-1231)

Fix use of weak PRNG in generation of dialback secrets (CVE-2016-1232)


Discovery 2016-01-08
Entry 2016-01-14
prosody
< 0.9.9

CVE-2016-1231
CVE-2016-1232
ports/206150
http://blog.prosody.im/prosody-0-9-9-security-release/