Candidate: CVE-2016-1231 PublicDate: 2016-01-12 20:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1231 https://prosody.im/security/advisory_20160108-1/ Description: Directory traversal vulnerability in the HTTP file-serving module (mod_http_files) in Prosody 0.9.x before 0.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) in an unspecified path. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N [5.9 MEDIUM] Patches_prosody: upstream_prosody: released (0.9.9-1) precise_prosody: ignored (reached end-of-life) precise/esm_prosody: DNE (precise was needs-triage) trusty_prosody: released (0.9.1-1ubuntu0.1) trusty/esm_prosody: DNE (trusty was released [0.9.1-1ubuntu0.1]) vivid_prosody: released (0.9.7-2+deb8u2build0.15.04.1) vivid/stable-phone-overlay_prosody: DNE vivid/ubuntu-core_prosody: DNE wily_prosody: released (0.9.8-1ubuntu0.1) xenial_prosody: not-affected (0.9.9-1) yakkety_prosody: not-affected (0.9.9-1) zesty_prosody: not-affected (0.9.9-1) devel_prosody: not-affected (0.9.9-1)