CVE-2008-3920: High severity bitlbee vulnerability

Published Aug 27, 2008
·
Updated

Description of problem: Bitlbee 1.2.2 was released, see the following changelog:

Version 1.2.2: - Security bugfix: It was possible to hijack accounts (without gaining access to the old account, it's simply an overwrite) - Some more stability improvements. - Fixed bug where people with non-lowercase nicks couldn't drop their account. - Easier upgrades of non-forking daemon mode servers (using the DEAF command). - Can be cross-compiled for Win32 now! (No support for SSL yet though, which makes it less useful for now.) - Exponential backoff on auto-reconnect. - Changing passwords gives less confusing feedback ("password is empty") now.

Finished 26 Aug 2008

Version-Release number of selected component (if applicable): bitlbee-1.2.1-1

Actual results: bitlbee-1.2.1-1

Expected results: bitlbee-1.2.2-1 ;-)

Additional info: I know, there's a security fix inside, but I'm unable to identify that one.

Other sources

Unspecified vulnerability in BitlBee before 1.2.2 allows remote attackers to "recreate" and "hijack" existing accounts via unspecified vectors.

MITRE

Affected Software

30 affected componentsFixes available
redhat/1.2.2<1
1
bitlbee BitlBee<=1.2.1
bitlbee BitlBee=0.71
bitlbee BitlBee=0.72
bitlbee BitlBee=0.73
bitlbee BitlBee=0.74
bitlbee BitlBee=0.74-a
bitlbee BitlBee=0.80
bitlbee BitlBee=0.81
bitlbee BitlBee=0.81-a
bitlbee BitlBee=0.82
bitlbee BitlBee=0.83
bitlbee BitlBee=0.84
bitlbee BitlBee=0.85
bitlbee BitlBee=0.85-a
bitlbee BitlBee=0.90
bitlbee BitlBee=0.90-a
bitlbee BitlBee=0.91
bitlbee BitlBee=0.92
bitlbee BitlBee=0.93
bitlbee BitlBee=0.93-a
bitlbee BitlBee=0.99
bitlbee BitlBee=1.0
bitlbee BitlBee=1.0.1
bitlbee BitlBee=1.0.2
bitlbee BitlBee=1.0.3
bitlbee BitlBee=1.0.4
bitlbee BitlBee=1.1-dev
bitlbee BitlBee=1.1.1-dev
bitlbee BitlBee=1.2

Event History

Sep 4, 2008
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description

Frequently Asked Questions

1

What is the severity of CVE-2008-3920?

CVE-2008-3920 has a high severity level, as it allows account hijacking without prior access to the old account.

2

How do I fix CVE-2008-3920?

To mitigate CVE-2008-3920, users should upgrade to Bitlbee version 1.2.2 or later.

3

What versions of Bitlbee are affected by CVE-2008-3920?

CVE-2008-3920 affects all versions of Bitlbee up to and including 1.2.1.

4

Can CVE-2008-3920 lead to data loss?

Yes, CVE-2008-3920 can result in the loss of account data through unauthorized overwrites.

5

Is there a patch available for CVE-2008-3920?

Yes, a patch is included in Bitlbee version 1.2.2 that addresses the vulnerabilities listed in CVE-2008-3920.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203