The mod_dialback module in Prosody before 0.9.9 does not properly generate random values for the secret token for server-to-server dialback authentication, which makes it easier for attackers to spoof servers via a brute force attack.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Prosody | Prosody | * | 0.9.8 (including) |
Prosody | Prosody | 0.9.0 (including) | 0.9.0 (including) |
Prosody | Prosody | 0.9.1 (including) | 0.9.1 (including) |
Prosody | Prosody | 0.9.2 (including) | 0.9.2 (including) |
Prosody | Prosody | 0.9.3 (including) | 0.9.3 (including) |
Prosody | Prosody | 0.9.4 (including) | 0.9.4 (including) |
Prosody | Prosody | 0.9.5 (including) | 0.9.5 (including) |
Prosody | Prosody | 0.9.6 (including) | 0.9.6 (including) |
Prosody | Prosody | 0.9.7 (including) | 0.9.7 (including) |
Prosody | Ubuntu | precise | * |
Prosody | Ubuntu | trusty | * |
Prosody | Ubuntu | upstream | * |
Prosody | Ubuntu | vivid | * |
Prosody | Ubuntu | wily | * |