UBUNTU-CVE-2021-32919
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-32919
Summary:
Details: An issue was discovered in Prosody before 0.11.9. The undocumented dialback_without_dialback option in mod_dialback enables an experimental feature for server-to-server authentication. It does not correctly authenticate remote server certificates, allowing a remote server to impersonate another server (when this option is enabled).
References: https://ubuntu.com/security/CVE-2021-32919, https://www.openwall.com/lists/oss-security/2021/05/13/1, https://prosody.im/security/advisory_20210512.txt, https://hg.prosody.im/trunk/rev/6be890ca492e, https://hg.prosody.im/trunk/rev/d0e9ffccdef9, https://blog.prosody.im/prosody-0.11.9-released/, https://www.cve.org/CVERecord?id=CVE-2021-32919
Affected packages
Package
Name: prosody
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
