Boletines de Vulnerabilidades

DSA-2895 prosody - security update

   
Software afectado Debian
 
A denial-of-service vulnerability has been reported in Prosody, a XMPPserver. If compression is enabled, an attacker might send highly-compressed XMLelements (attack known as zip bomb) over XMPP streams and consume allthe resources of the server.

More info:

https://www.debian.org/security/2014/dsa-2895