{"id":"openSUSE-SU-2021:0728-1","summary":"Security update for prosody","details":"This update for prosody fixes the following issues:\n\nprosody was updated to 0.11.9:\n\nSecurity:\n\n* mod_limits, prosody.cfg.lua: Enable rate limits by default\n* certmanager: Disable renegotiation by default\n* mod_proxy65: Restrict access to local c2s connections by default\n* util.startup: Set more aggressive defaults for GC\n* mod_c2s, mod_s2s, mod_component, mod_bosh, mod_websockets: Set default stanza size limits\n* mod_authinternal{plain,hashed}: Use constant-time string comparison for secrets\n* mod_dialback: Remove dialback-without-dialback feature\n* mod_dialback: Use constant-time comparison with hmac\n\nMinor changes:\n\n* util.hashes: Add constant-time string comparison (binding to CRYPTO_memcmp)\n* mod_c2s: Don’t throw errors in async code when connections are gone\n* mod_c2s: Fix traceback in session close when conn is nil\n* core.certmanager: Improve detection of LuaSec/OpenSSL capabilities\n* mod_saslauth: Use a defined SASL error\n* MUC: Add support for advertising muc#roomconfig_allowinvites in room disco#info\n* mod_saslauth: Don’t throw errors in async code when connections are gone\n* mod_pep: Advertise base pubsub feature (fixes #1632: mod_pep missing pubsub feature in disco)\n* prosodyctl check config: Add ‘gc’ to list of global options\n* prosodyctl about: Report libexpat version if known\n* util.xmppstream: Add API to dynamically configure the stanza size limit for a stream\n* util.set: Add is_set() to test if an object is a set\n* mod_http: Skip IP resolution in non-proxied case\n* mod_c2s: Log about missing conn on async state changes\n* util.xmppstream: Reduce internal default xmppstream limit to 1MB\n\nRelevant: https://prosody.im/security/advisory_20210512\n\n* boo#1186027: Prosody XMPP server advisory 2021-05-12\n* CVE-2021-32919\n* CVE-2021-32917\n* CVE-2021-32917\n* CVE-2021-32920\n* CVE-2021-32918\n\nUpdate to 0.11.8:\n\nSecurity:\n* mod_saslauth: Disable ‘tls-unique’ channel binding with TLS 1.3 (#1542)\n\nFixes and improvements:\n\n* net.websocket.frames: Improve websocket masking performance by using the new util.strbitop\n* util.strbitop: Library for efficient bitwise operations on strings\n\nMinor changes:\n\n* MUC: Correctly advertise whether the subject can be changed (#1155)\n* MUC: Preserve disco ‘node’ attribute (or lack thereof) in responses (#1595)\n* MUC: Fix logic bug causing unnecessary presence to be sent (#1615)\n* mod_bosh: Fix error if client tries to connect to component (#425)\n* mod_bosh: Pick out the ‘wait’ before checking it instead of earlier\n* mod_pep: Advertise base PubSub feature (#1632)\n* mod_pubsub: Fix notification stanza type setting (#1605)\n* mod_s2s: Prevent keepalives before client has established a stream\n* net.adns: Fix bug that sent empty DNS packets (#1619)\n* net.http.server: Don’t send Content-Length on 1xx/204 responses (#1596)\n* net.websocket.frames: Fix length calculation bug (#1598)\n* util.dbuffer: Make length API in line with Lua strings\n* util.dbuffer: Optimize substring operations\n* util.debug: Fix locals being reported under wrong stack frame in some cases\n* util.dependencies: Fix check for Lua bitwise operations library (#1594)\n* util.interpolation: Fix combination of filters and fallback values #1623\n* util.promise: Preserve tracebacks\n* util.stanza: Reject ASCII control characters (#1606)\n* timers: Ensure timers can’t block other processing (#1620)\n\nUpdate to 0.11.7:\n\nSecurity:\n\n* mod_websocket: Enforce size limits on received frames (fixes #1593)\n\nFixes and improvements:\n\n* mod_c2s, mod_s2s: Make stanza size limits configurable\n* Add configuration options to control Lua garbage collection parameters\n* net.http: Backport SNI support for outgoing HTTP requests (#409)\n* mod_websocket: Process all data in the buffer on close frame and connection errors (fixes #1474, #1234)\n* util.indexedbheap: Fix heap data structure corruption, causing some timers to fail after a reschedule (fixes #1572)\n\nUpdate to 0.11.6:\n\nFixes and improvements:\n\n* mod_storage_internal: Fix error in time limited queries on items without ‘when’ field, fixes #1557\n* mod_carbons: Fix handling of incoming MUC PMs #1540\n* mod_csi_simple: Consider XEP-0353: Jingle Message Initiation important\n* mod_http_files: Avoid using inode in etag, fixes #1498: Fail to download file on FreeBSD\n* mod_admin_telnet: Create a DNS resolver per console session (fixes #1492: Telnet console DNS commands reduced usefulness)\n* core.certmanager: Move EECDH ciphers before EDH in default cipherstring (fixes #1513)\n* mod_s2s: Escape invalid XML in loggin (same way as mod_c2s) (fixes #1574: Invalid XML input on s2s connection is logged unescaped)\n* mod_muc: Allow control over the server-admins-are-room-owners feature (see #1174)\n* mod_muc_mam: Remove spoofed archive IDs before archiving (fixes #1552: MUC MAM may strip its own archive id)\n* mod_muc_mam: Fix stanza id filter event name, fixes #1546: mod_muc_mam does not strip spoofed stanza ids\n* mod_muc_mam: Fix missing advertising of XEP-0359, fixes #1547: mod_muc_mam does not advertise stanza-id\n\nMinor changes:\n\n* net.http API: Add request:cancel() method\n* net.http API: Fix traceback on invalid URL passed to request()\n* MUC: Persist affiliation_data in new MUC format\n* mod_websocket: Fire event on session creation (thanks Aaron van Meerten)\n* MUC: Always include ‘affiliation’/‘role’ attributes, defaulting to ‘none’ if nil\n* mod_tls: Log when certificates are (re)loaded\n* mod_vcard4: Report correct error condition (fixes #1521: mod_vcard4 reports wrong error)\n* net.http: Re-expose destroy_request() function (fixes unintentional API breakage)\n* net.http.server: Strip port from Host header in IPv6 friendly way (fix #1302)\n* util.prosodyctl: Tell prosody do daemonize via command line flag (fixes #1514)\n* SASL: Apply saslprep where necessary, fixes #1560: Login fails if password contains special chars\n* net.http.server: Fix reporting of missing Host header\n* util.datamanager API: Fix iterating over “users” (thanks marc0s)\n* net.resolvers.basic: Default conn_type to ‘tcp’ consistently if unspecified (thanks marc0s)\n* mod_storage_sql: Fix check for deletion limits (fixes #1494)\n* mod_admin_telnet: Handle unavailable cipher info (fixes #1510: mod_admin_telnet backtrace)\n* Log warning when using prosodyctl start/stop/restart\n* core.certmanager: Look for privkey.pem to go with fullchain.pem (fixes #1526)\n* mod_storage_sql: Add index covering sort_id to improve performance (fixes #1505)\n* mod_mam,mod_muc_mam: Allow other work to be performed during archive cleanup (fixes #1504)\n* mod_muc_mam: Don’t strip MUC tags, fix #1567: MUC tags stripped by mod_muc_mam\n* mod_pubsub, mod_pep: Ensure correct number of children of (fixes #1496)\n* mod_register_ibr: Add FORM_TYPE as required by XEP-0077 (fixes #1511)\n* mod_muc_mam: Fix traceback saving message from non-occupant (fixes #1497)\n* util.startup: Remove duplicated initialization of logging (fix #1527: startup: Logging initialized twice)\n","modified":"2026-03-11T07:33:02.135048Z","published":"2021-05-14T21:17:01Z","related":["CVE-2021-32917","CVE-2021-32918","CVE-2021-32919","CVE-2021-32920"],"upstream":["CVE-2021-32917","CVE-2021-32918","CVE-2021-32919","CVE-2021-32920"],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/QFZF2R5S5FEXEQIW4Q7P3QW6HA46PJMX/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1186027"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-32917"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-32918"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-32919"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-32920"}],"affected":[{"package":{"name":"prosody","ecosystem":"openSUSE:Leap 15.2","purl":"pkg:rpm/opensuse/prosody&distro=openSUSE%20Leap%2015.2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.11.9-lp152.2.3.1"}]}],"ecosystem_specific":{"binaries":[{"prosody":"0.11.9-lp152.2.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2021:0728-1.json"}}],"schema_version":"1.7.5"}