Alerts This Week
Warning Icon 1 535
Alerts This Week
Warning Icon 1 535

Gentoo: GLSA-200807-12 Normal: BitchX Multiple Execution Risks

gentoo
Calendar Grey July 22, 2008
Dist Gentoo Esm H88
Numerous BitchX vulnerabilities could enable remote code execution or symlink exploits. Important security notice for all users.
Multiple vulnerabilities in BitchX may allow for the remote execution of arbitrary code or symlink attacks.

Summary

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Gentoo Linux Security Advisory                           GLSA 200807-12
                                            https://security.gentoo.org/

Severity: Normal Title: BitchX: Multiple vulnerabilities Date: July 21, 2008 Bugs: #190667 ID: 200807-12

Synopsis ======= Multiple vulnerabilities in BitchX may allow for the remote execution of arbitrary code or symlink attacks.
Background ========= BitchX is an IRC client.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-irc/bitchx <= 1.1-r4 Vulnerable! ------------------------------------------------------------------- NOTE: Certain packages are still vulnerable. Users should migrate to another package if one is available or wait for the existing packages to be marked stable by their architecture maintainers.
========== bannedit reported a boundary error when handling overly long IRC MODE messages (CVE-2007-4584). Nico Golde reported an insecure creation of a temporary file within the e_hostname() function (CVE-2007-5839).
Impact ===...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns


Warning: Undefined array key "advisory_info" in /var/www/www.linuxsecurity.com-443/html/tmp/regularlabs/custom_php/3269520_4c9dbbdde36eef04251a4ced7eac4df9 on line 11

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround

Related News

Your message here