CVE-2017-18265: Debian Linux

High severity, CVSS 7.5. EPSS: 1.7% chance of exploitation in the next 30 days.

Prosody before 0.10.0 allows remote attackers to cause a denial of service (application crash), related to an incompatibility with certain versions of the LuaSocket library, such as the lua-socket package from Debian stretch. The attacker needs to trigger a stream error. A crash can be observed in, for example, the c2s module.

Affected products

  • Debian Debian Linux: version 9.0 only
  • Prosody Prosody: before 0.10.0 (fixed in 0.10.0)

Published 2018-05-09. Last modified 2026-06-17.