Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Fedora 25: Remote DoS Fix for BitlBee Security Update Released

fedora
Calendar Grey February 9, 2017
Dist Fedora Esm H88
BitlBee 3.5.1 security patch addresses remote DoS vulnerabilities caused by unidentified contacts. Ensure you install the update via dnf on Fedora 25.
BitlBee 3.5.1 (30 Jan 2017) file transfer requests from unknown contacts

Summary

Bitlbee is an IRC to other chat networks gateway. Bitlbee can be used as

an IRC server which forwards everything you say to people on other chat

networks like XMPP/Jabber (including Google Talk and Hipchat), MSN/Skype,

AIM and ICQ, the Twitter microblogging network (and all other Twitter API

compatible services like status.net).

Update Information:

BitlBee 3.5.1 (30 Jan 2017) =========================== - purple: Fix crash on file transfer requests from unknown contacts. This was the result of an incomplete fix in the previous release and may result in remote DoS. Read the full security advisory at: - After some investigation we decided to reclassify a crash fix from the previous release as a security issue. Read the full security advisory at: - Included help.txt in the release tarball, which was missing in the previous release and resulted in adding python as a build dependency. The release tarball of 3.5.1 does not require python.

Change Log

References

Fedora Update Notification FEDORA-2017-deb82f0c0d 2017-02-09 01:14:52.524055
Name : bitlbee Product : Fedora 25 Version : 3.5.1 Release : 1.fc25 URL : https://www.bitlbee.org/main.php/news.r.html Summary : IRC to other chat networks gateway Description : Bitlbee is an IRC to other chat networks gateway. Bitlbee can be used as an IRC server which forwards everything you say to people on other chat networks like XMPP/Jabber (including Google Talk and Hipchat), MSN/Skype, AIM and ICQ, the Twitter microblogging network (and all other Twitter API compatible services like status.net).

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade bitlbee' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
important
Lowest
Low
Medium
High
Critical

Name: bitlbee
Product: Fedora 25
Version: 3.5.1
Release: 1.fc25
Summary: IRC to other chat networks gateway

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here