It was discovered that bitlbee, an IRC to other chat networks gateway, contained issues that allowed a remote attacker to cause a denial of service (via application crash), or potentially execute arbitrary commands. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3853-1
Multiple vulnerabilities in Bitlbee may allow to bypass security restrictions and hijack accounts.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200809-14 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: BitlBee: Security bypass Date: September 23, 2008 Bugs: #236160 ID: 200809-14 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities in Bitlbee may allow to bypass security restrictions and hijack accounts. Background ========= BitlBee is an IRC to IM gateway that support multiple IM protocols. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-im/bitlbee < 1.2.3 > = 1.2.3 Description ========== Multiple unspecified vulnerabilities were reported, including a NULL pointer dereference. Impact ===== A remote attacker could exploit these vulnerabilities to overwrite existing IM accounts. Workaround ========= There is no known workaround at this time. Resolution ========= All BitlBee users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-im/bitlbee-1.2.3" References ========= [ 1 ] CVE-2008-3920 https://www.cve.org/CVERecord?id=CVE-2008-3920 [ 2 ] CVE-2008-3969 https://www.cve.org/CVERecord?id=CVE-2008-3969 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200809-14 Concerns? ======== Security is aprimary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to
Get the latest Linux and open source security news straight to your inbox.