#488 Version of LuaExpat does not support stanza size limits

Reporter taekfang
Owner MattJ
Created
Updated
Stars ★★★ (3)  
Tags
  • Type-Defect
  • Priority-Medium
  • Packages
  • Status-Accepted
  1. taekfang on

    *What steps will reproduce the problem?* 1. prosodyctl start *2.* *3.* *What is the expected output? What do you see instead?* Prosody Started *What version of the product are you using? On what operating system?* Latest Available from Repos *Please provide any additional information below.* taek@server:/etc/prosody$ sudo prosodyctl status general error The version of LuaExpat on your system does not support stanza size limits, which may leave servers on untrusted networks (e.g. the internet) vulnerable to denial-of-service attacks. You should upgrade to LuaExpat 1.3.0 or higher as soon as possible. See http://prosody.im/doc/depends#luaexpat for more information. Prosody is running with PID 16930 Additional Information: liblua5.1-expat0 is installed. Ubuntu 12.04.5 LTS Server i586

  2. taekfang on

    Prosody Version: 0.9.8-1~precise2

  3. hosarsiph.valle on

    I have the same issue. Using ubuntu 14.04 and Prosody 0.9.8

  4. Zash on

    We should publish an updated lua-expat in our repos. Maybe tone down that warning a bit too, unless compression is enabled.

    Changes
    • owner MattJ
    • tag Status-Accepted
  5. sokai on

    @Zash If it's possible I appreciate your idea very much! No backports are available for trusty … Thanks a lot and best regards!

  6. Zash on

    Changes
    • tags Packages

New comment