7.5
CWE
264
Advisory Published
CVE Published
Updated

CVE-2008-3920

First published: Wed Aug 27 2008(Updated: )

Description of problem: Bitlbee 1.2.2 was released, see the following changelog: Version 1.2.2: - Security bugfix: It was possible to hijack accounts (without gaining access to the old account, it's simply an overwrite) - Some more stability improvements. - Fixed bug where people with non-lowercase nicks couldn't drop their account. - Easier upgrades of non-forking daemon mode servers (using the DEAF command). - Can be cross-compiled for Win32 now! (No support for SSL yet though, which makes it less useful for now.) - Exponential backoff on auto-reconnect. - Changing passwords gives less confusing feedback ("password is empty") now. Finished 26 Aug 2008 Version-Release number of selected component (if applicable): bitlbee-1.2.1-1 Actual results: bitlbee-1.2.1-1 Expected results: bitlbee-1.2.2-1 ;-) Additional info: I know, there's a security fix inside, but I'm unable to identify that one.

Credit: cve@mitre.org

Affected SoftwareAffected VersionHow to fix
Bitlbee Bitlbee=0.71
Bitlbee Bitlbee=0.72
Bitlbee Bitlbee=1.1-dev
Bitlbee Bitlbee=0.85
Bitlbee Bitlbee=0.85-a
Bitlbee Bitlbee=0.90
Bitlbee Bitlbee=0.84
Bitlbee Bitlbee=1.1.1-dev
Bitlbee Bitlbee=1.0.3
Bitlbee Bitlbee=0.80
Bitlbee Bitlbee=0.81-a
Bitlbee Bitlbee=0.92
Bitlbee Bitlbee=1.0.2
Bitlbee Bitlbee<=1.2.1
Bitlbee Bitlbee=0.93-a
Bitlbee Bitlbee=0.74-a
Bitlbee Bitlbee=0.90-a
Bitlbee Bitlbee=0.74
Bitlbee Bitlbee=1.0.1
Bitlbee Bitlbee=1.0
Bitlbee Bitlbee=1.0.4
Bitlbee Bitlbee=0.81
Bitlbee Bitlbee=0.93
Bitlbee Bitlbee=0.83
Bitlbee Bitlbee=0.99
Bitlbee Bitlbee=0.91
Bitlbee Bitlbee=0.82
Bitlbee Bitlbee=1.2
Bitlbee Bitlbee=0.73
redhat/1.2.2<1
1

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203