CVE

Id
50444  
CVE No.
CVE-2011-2532  
Status
Candidate  
Description
The json.decode function in util/json.lua in Prosody 0.8.x before 0.8.1 might allow remote attackers to cause a denial of service (infinite loop) via invalid JSON data, as demonstrated by truncated data.  
Phase
Assigned (20110622)  
Votes
None (candidate not yet proposed)  
Comments