-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Gentoo Linux Security Advisory GLSA 200807-12
https://security.gentoo.org/
Severity: Normal
Title: BitchX: Multiple vulnerabilities
Date: July 21, 2008
Bugs: #190667
ID: 200807-12
Synopsis
=======
Multiple vulnerabilities in BitchX may allow for the remote execution
of arbitrary code or symlink attacks.
Background
=========
BitchX is an IRC client.
Affected packages
================
-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 net-irc/bitchx <= 1.1-r4 Vulnerable!
-------------------------------------------------------------------
NOTE: Certain packages are still vulnerable. Users should migrate
to another package if one is available or wait for the
existing packages to be marked stable by their
architecture maintainers.
==========
bannedit reported a boundary error when handling overly long IRC MODE
messages (CVE-2007-4584). Nico Golde reported an insecure creation of a
temporary file within the e_hostname() function (CVE-2007-5839).
Impact
===...Read the Full Advisory
style>.gentoo_availability{display:block;}
Warning: Undefined array key "advisory_info" in /var/www/www.linuxsecurity.com-443/html/tmp/regularlabs/custom_php/3269520_4c9dbbdde36eef04251a4ced7eac4df9 on line 11
Get the latest Linux and open source security news straight to your inbox.