FreeBSD : py-matrix-synapse -- malformed events may prevent users from joining federated rooms (2327234d-fc4b-11ea-adef-641c67a117d8)

high Nessus Plugin ID 140725

Language:

Synopsis

The remote FreeBSD host is missing one or more security-related updates.

Description

Affected Synapse versions assume that all events have an 'origin' field set. If an event without the 'origin' field is sent into a federated room, servers not already joined to the room will be unable to do so due to failing to fetch the malformed event. Impact : An attacker could cause a denial of service by deliberately sending a malformed event into a room, thus preventing new servers (and thus their users) from joining the room.

Solution

Update the affected packages.

See Also

https://github.com/matrix-org/synapse/issues/8319

https://github.com/matrix-org/synapse/pull/8324

https://github.com/matrix-org/synapse/blob/v1.19.3/CHANGES.md

http://www.nessus.org/u?95ea8b63

Plugin Details

Severity: High

ID: 140725

File Name: freebsd_pkg_2327234dfc4b11eaadef641c67a117d8.nasl

Version: 1.1

Type: local

Published: 9/22/2020

Updated: 9/22/2020

Supported Sensors: Nessus

Vulnerability Information

CPE: p-cpe:/a:freebsd:freebsd:py36-matrix-synapse, p-cpe:/a:freebsd:freebsd:py37-matrix-synapse, p-cpe:/a:freebsd:freebsd:py38-matrix-synapse, cpe:/o:freebsd:freebsd

Required KB Items: Host/local_checks_enabled, Host/FreeBSD/release, Host/FreeBSD/pkg_info

Patch Publication Date: 9/21/2020

Vulnerability Publication Date: 9/16/2020