Bug 1296983 - (CVE-2016-1231) CVE-2016-1231 prosody: path traversal vulnerability in mod_http_files
CVE-2016-1231 prosody: path traversal vulnerability in mod_http_files
Status: NEW
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
Unspecified Unspecified
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
impact=moderate,public=20160108,repor...
: Security
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2016-01-08 10:44 EST by Robert Scheck
Modified: 2016-01-27 11:12 EST (History)
1 user (show)

See Also:
Fixed In Version: prosody 0.9.9
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed:
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Robert Scheck 2016-01-08 10:44:34 EST
A flaw was found in Prosody's HTTP file-serving module (mod_http_files)
that allows it to serve requests outside of the configured public root
directory. This could allow attackers access to private files including
sensitive data.

External References:

https://prosody.im/security/advisory_20160108-1/
Comment 1 Martin Prpic 2016-01-11 03:34:02 EST
Affected configurations
-----------------------

The default configuration has mod_http_files disabled, and is not
vulnerable. Additionally, configurations where mod_http_files serves
files at the root URL (e.g. not /files/ prefix, using http_paths) are
not vulnerable.

Temporary mitigation
--------------------

Disable mod_http_files and any community modules that depend on it.
Comment 2 Martin Prpic 2016-01-11 03:35:07 EST
This has been fixed in:

prosody-0.9.9-1.fc24
prosody-0.9.9-1.fc22
prosody-0.9.9-1.el5
prosody-0.9.9-1.fc23
prosody-0.9.9-1.el7
prosody-0.9.9-1.el6
Comment 3 Fedora Update System 2016-01-20 16:55:58 EST
prosody-0.9.9-2.fc23 has been pushed to the Fedora 23 stable repository. If problems still persist, please make note of it in this bug report.
Comment 4 Fedora Update System 2016-01-20 23:48:44 EST
prosody-0.9.9-2.fc22 has been pushed to the Fedora 22 stable repository. If problems still persist, please make note of it in this bug report.
Comment 5 Fedora Update System 2016-01-21 19:57:46 EST
prosody-0.9.9-2.el6 has been pushed to the Fedora EPEL 6 stable repository. If problems still persist, please make note of it in this bug report.
Comment 6 Fedora Update System 2016-01-26 10:42:25 EST
prosody-0.9.9-2.el5 has been pushed to the Fedora EPEL 5 stable repository. If problems still persist, please make note of it in this bug report.
Comment 7 Fedora Update System 2016-01-27 11:12:56 EST
prosody-0.9.9-2.el7 has been pushed to the Fedora EPEL 7 stable repository. If problems still persist, please make note of it in this bug report.

Note You need to log in before you can comment on or make changes to this bug.