LWN.net Logo

bitlbee: account hijack

Package(s):bitlbee CVE #(s):CVE-2008-3920 CVE-2008-3969
Created:September 5, 2008 Updated:September 24, 2008
Description: Upstream released Bitlbee 1.2.2 with the following changes to the former release: - Security bugfix: It was possible to hijack accounts (without gaining access to the old account, it's simply an overwrite) - Some more stability improvements. The 1.2.3 release "completes" the fix for thsese problems.
Alerts:
Fedora FEDORA-2008-7274 2008-09-05
Fedora FEDORA-2008-7712 2008-09-05
Fedora FEDORA-2008-7761 2008-09-11
Fedora FEDORA-2008-7830 2008-09-11
Gentoo 200809-14 2008-09-23

(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds