Bug 1296983 (CVE-2016-1231) - CVE-2016-1231 prosody: path traversal vulnerability in mod_http_files
Summary: CVE-2016-1231 prosody: path traversal vulnerability in mod_http_files
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2016-1231
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: Unspecified
OS: Unspecified
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2016-01-08 15:44 UTC by Robert Scheck
Modified: 2021-03-17 20:30 UTC (History)
1 user (show)

Fixed In Version: prosody 0.9.9
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2021-03-17 20:30:55 UTC
Embargoed:


Attachments (Terms of Use)

Description Robert Scheck 2016-01-08 15:44:34 UTC
A flaw was found in Prosody's HTTP file-serving module (mod_http_files)
that allows it to serve requests outside of the configured public root
directory. This could allow attackers access to private files including
sensitive data.

External References:

https://prosody.im/security/advisory_20160108-1/

Comment 1 Martin Prpič 2016-01-11 08:34:02 UTC
Affected configurations
-----------------------

The default configuration has mod_http_files disabled, and is not
vulnerable. Additionally, configurations where mod_http_files serves
files at the root URL (e.g. not /files/ prefix, using http_paths) are
not vulnerable.

Temporary mitigation
--------------------

Disable mod_http_files and any community modules that depend on it.

Comment 2 Martin Prpič 2016-01-11 08:35:07 UTC
This has been fixed in:

prosody-0.9.9-1.fc24
prosody-0.9.9-1.fc22
prosody-0.9.9-1.el5
prosody-0.9.9-1.fc23
prosody-0.9.9-1.el7
prosody-0.9.9-1.el6

Comment 3 Fedora Update System 2016-01-20 21:55:58 UTC
prosody-0.9.9-2.fc23 has been pushed to the Fedora 23 stable repository. If problems still persist, please make note of it in this bug report.

Comment 4 Fedora Update System 2016-01-21 04:48:44 UTC
prosody-0.9.9-2.fc22 has been pushed to the Fedora 22 stable repository. If problems still persist, please make note of it in this bug report.

Comment 5 Fedora Update System 2016-01-22 00:57:46 UTC
prosody-0.9.9-2.el6 has been pushed to the Fedora EPEL 6 stable repository. If problems still persist, please make note of it in this bug report.

Comment 6 Fedora Update System 2016-01-26 15:42:25 UTC
prosody-0.9.9-2.el5 has been pushed to the Fedora EPEL 5 stable repository. If problems still persist, please make note of it in this bug report.

Comment 7 Fedora Update System 2016-01-27 16:12:56 UTC
prosody-0.9.9-2.el7 has been pushed to the Fedora EPEL 7 stable repository. If problems still persist, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.