prosody: security bump to version 0.10.2
authorFabrice Fontaine <fontaine.fabrice@gmail.com>
Sun, 18 Nov 2018 12:14:03 +0000 (13:14 +0100)
committerPeter Korsgaard <peter@korsgaard.com>
Sun, 18 Nov 2018 17:51:08 +0000 (18:51 +0100)
commit0b950434950489aa897ac04d45d0293269dd8c17
tree8cdf3ecf91da77691e786685e2e6a86b2bc2dcb9
parent305e4487e5c18ed89bf2aa106b2068f9dce686fb
prosody: security bump to version 0.10.2

This fixes a cross-host authentication vulnerability, CVE-2018-10847.
The issue affects Prosody instances that have multiple virtual hosts
(including anonymous authenticated hosts):
https://blog.prosody.im/prosody-0-10-2-security-release

A full security advisory is available at
https://prosody.im/security/advisory_20180531

Compute hashes locally as they are no more available on
https://prosody.im/downloads/source/{MD5,SHA1,SHA256,SHA512}SUMS

Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
package/prosody/prosody.hash
package/prosody/prosody.mk