CVE Vulnerabilities

CVE-2016-1232

Published: Jan 12, 2016 | Modified: Jun 09, 2016
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

The mod_dialback module in Prosody before 0.9.9 does not properly generate random values for the secret token for server-to-server dialback authentication, which makes it easier for attackers to spoof servers via a brute force attack.

Affected Software

Name Vendor Start Version End Version
Prosody Prosody * 0.9.8 (including)
Prosody Prosody 0.9.0 (including) 0.9.0 (including)
Prosody Prosody 0.9.1 (including) 0.9.1 (including)
Prosody Prosody 0.9.2 (including) 0.9.2 (including)
Prosody Prosody 0.9.3 (including) 0.9.3 (including)
Prosody Prosody 0.9.4 (including) 0.9.4 (including)
Prosody Prosody 0.9.5 (including) 0.9.5 (including)
Prosody Prosody 0.9.6 (including) 0.9.6 (including)
Prosody Prosody 0.9.7 (including) 0.9.7 (including)
Prosody Ubuntu precise *
Prosody Ubuntu trusty *
Prosody Ubuntu upstream *
Prosody Ubuntu vivid *
Prosody Ubuntu wily *

References