GLSA Advocate
Joined: 12 May 2004 Posts: 2663
|
Posted: Tue Sep 23, 2008 10:26 pm Post subject: [ GLSA 200809-14 ] BitlBee: Security bypass |
|
|
Gentoo Linux Security Advisory
Title: BitlBee: Security bypass (GLSA 200809-14)
Severity: normal
Exploitable: remote
Date: September 23, 2008
Bug(s): #236160
ID: 200809-14
Synopsis
Multiple vulnerabilities in Bitlbee may allow to bypass security restrictions and hijack accounts.
Background
BitlBee is an IRC to IM gateway that support multiple IM protocols.
Affected Packages
Package: net-im/bitlbee
Vulnerable: < 1.2.3
Unaffected: >= 1.2.3
Architectures: All supported architectures
Description
Multiple unspecified vulnerabilities were reported, including a NULL pointer dereference.
Impact
A remote attacker could exploit these vulnerabilities to overwrite existing IM accounts.
Workaround
There is no known workaround at this time.
Resolution
All BitlBee users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=net-im/bitlbee-1.2.3" |
References
CVE-2008-3920
CVE-2008-3969 |
|