Описание
ejabberd before 2.1.13 does not enforce the starttls_required setting when compression is used, which causes clients to establish connections without encryption.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| ejabberd | fixed | 14.07-3 | package | |
| ejabberd | no-dsa | squeeze | package |
Примечания
http://mail.jabber.org/pipermail/operators/2014-October/002438.html
Patch https://github.com/processone/ejabberd/commit/7bdc1151b
EPSS
Связанные уязвимости
ejabberd before 2.1.13 does not enforce the starttls_required setting when compression is used, which causes clients to establish connections without encryption.
ejabberd before 2.1.13 does not enforce the starttls_required setting when compression is used, which causes clients to establish connections without encryption.
ejabberd before 2.1.13 does not enforce the starttls_required setting when compression is used, which causes clients to establish connections without encryption.
EPSS