CVE-2011-2532Infinite Loop in Prosody

CWE-3994 documents4 sources
Severity
5.0MEDIUMNVD
EPSS
0.5%
top 32.51%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 22
Latest updateMay 17

Description

The json.decode function in util/json.lua in Prosody 0.8.x before 0.8.1 might allow remote attackers to cause a denial of service (infinite loop) via invalid JSON data, as demonstrated by truncated data.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

debiandebian/prosody< prosody 0.8.1-1 (bookworm)
Debianprosody/prosody< 0.8.1-1+3
NVDprosody/prosody0.8.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-mq6h-jh39-cjg8: The json2022-05-17
OSV
CVE-2011-2532: The json2011-06-22

📋Vendor Advisories

1
Debian
CVE-2011-2532: prosody - The json.decode function in util/json.lua in Prosody 0.8.x before 0.8.1 might al...2011
CVE-2011-2532 — Infinite Loop in Debian Prosody | cvebase