MGASA-2014-0417

Source
https://advisories.mageia.org/MGASA-2014-0417.html
Import Source
https://advisories.mageia.org/MGASA-2014-0417.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2014-0417
Related
Published
2014-10-23T13:27:57Z
Modified
2014-10-23T13:07:24Z
Summary
Updated ejabberd packages fix security vulnerability
Details

A flaw was discovered in ejabberd that allows clients to connect with an unencrypted connection even if starttls_required is set (CVE-2014-8760).

References
Credits

Affected packages

Mageia:4 / ejabberd

Package

Name
ejabberd
Purl
pkg:rpm/mageia/ejabberd?distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.1.13-3.1.mga4

Ecosystem specific

{
    "section": "core"
}

Mageia:3 / ejabberd

Package

Name
ejabberd
Purl
pkg:rpm/mageia/ejabberd?distro=mageia-3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.1.13-1.1.mga3

Ecosystem specific

{
    "section": "core"
}