VYPR
High severity7.5NVD Advisory· Published May 9, 2018· Updated Jun 17, 2026

CVE-2017-18265

CVE-2017-18265

Description

Prosody before 0.10.0 allows remote attackers to cause a denial of service (application crash), related to an incompatibility with certain versions of the LuaSocket library, such as the lua-socket package from Debian stretch. The attacker needs to trigger a stream error. A crash can be observed in, for example, the c2s module.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • Prosody/Prosody2 versions
    cpe:2.3:a:prosody:prosody:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:prosody:prosody:*:*:*:*:*:*:*:*range: <0.10.0
    • (no CPE)range: <0.10.0
  • cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
  • Bjc/Prosodyinferred
    Range: <0.10.0
  • Debian/lua-socketllm-create
    Range: stretch

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.