This bug was fixed in the package prosody - 0.9.1-1ubuntu0.1
---------------
prosody (0.9.1-1ubuntu0.1) trusty-security; urgency=medium
* SECURITY UPDATE: path traversal vulnerability in mod_http_files
- debian/patches/CVE-2016-1231.patch
- CVE-2016-1231
- LP: #1532943
* SECURITY UPDATE: use of weak PRNG in generation of dialback secrets
- debian/patches/CVE-2016-1232.patch
- CVE-2016-1232
- LP: #1532943
-- Felix Geyer <[email protected]> Mon, 11 Jan 2016 19:21:33 +0100
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1532943
Title:
CVE-2016-1231 and CVE-2016-1232
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/prosody/+bug/1532943/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs