CVE
- Id
- 87052
- CVE No.
- CVE-2016-0756
- Status
- Candidate
- Description
- The generate_dialback function in the mod_dialback module in Prosody before 0.9.10 does not properly separate fields when generating dialback keys, which allows remote attackers to spoof XMPP network domains via a crafted stream id and domain name that is included in the target domain as a suffix.
- Phase
- Assigned (20151216)
- Votes
- None (candidate not yet proposed)
- Comments