Full Disclosure mailing list archives
[ GLSA 200809-14 ] BitlBee: Security bypass
From: Pierre-Yves Rofes <py () gentoo org>
Date: Tue, 23 Sep 2008 23:33:35 +0200
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 200809-14
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Severity: Normal
Title: BitlBee: Security bypass
Date: September 23, 2008
Bugs: #236160
ID: 200809-14
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Synopsis
========
Multiple vulnerabilities in Bitlbee may allow to bypass security
restrictions and hijack accounts.
Background
==========
BitlBee is an IRC to IM gateway that support multiple IM protocols.
Affected packages
=================
-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 net-im/bitlbee < 1.2.3 >= 1.2.3
Description
===========
Multiple unspecified vulnerabilities were reported, including a NULL
pointer dereference.
Impact
======
A remote attacker could exploit these vulnerabilities to overwrite
existing IM accounts.
Workaround
==========
There is no known workaround at this time.
Resolution
==========
All BitlBee users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=net-im/bitlbee-1.2.3"
References
==========
[ 1 ] CVE-2008-3920
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3920
[ 2 ] CVE-2008-3969
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3969
Availability
============
This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:
http://security.gentoo.org/glsa/glsa-200809-14.xml
Concerns?
=========
Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users machines is of utmost
importance to us. Any security concerns should be addressed to
security () gentoo org or alternatively, you may file a bug at
http://bugs.gentoo.org.
License
=======
Copyright 2008 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).
The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.
http://creativecommons.org/licenses/by-sa/2.5
Attachment:
signature.asc
Description: OpenPGP digital signature
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- [ GLSA 200809-14 ] BitlBee: Security bypass Pierre-Yves Rofes (Sep 23)
