CVE-2008-3920: High severity bitlbee vulnerability
Description of problem: Bitlbee 1.2.2 was released, see the following changelog:
Version 1.2.2: - Security bugfix: It was possible to hijack accounts (without gaining access to the old account, it's simply an overwrite) - Some more stability improvements. - Fixed bug where people with non-lowercase nicks couldn't drop their account. - Easier upgrades of non-forking daemon mode servers (using the DEAF command). - Can be cross-compiled for Win32 now! (No support for SSL yet though, which makes it less useful for now.) - Exponential backoff on auto-reconnect. - Changing passwords gives less confusing feedback ("password is empty") now.
Finished 26 Aug 2008
Version-Release number of selected component (if applicable): bitlbee-1.2.1-1
Actual results: bitlbee-1.2.1-1
Expected results: bitlbee-1.2.2-1 ;-)
Additional info: I know, there's a security fix inside, but I'm unable to identify that one.
Other sources
Unspecified vulnerability in BitlBee before 1.2.2 allows remote attackers to "recreate" and "hijack" existing accounts via unspecified vectors.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-3920?
CVE-2008-3920 has a high severity level, as it allows account hijacking without prior access to the old account.
How do I fix CVE-2008-3920?
To mitigate CVE-2008-3920, users should upgrade to Bitlbee version 1.2.2 or later.
What versions of Bitlbee are affected by CVE-2008-3920?
CVE-2008-3920 affects all versions of Bitlbee up to and including 1.2.1.
Can CVE-2008-3920 lead to data loss?
Yes, CVE-2008-3920 can result in the loss of account data through unauthorized overwrites.
Is there a patch available for CVE-2008-3920?
Yes, a patch is included in Bitlbee version 1.2.2 that addresses the vulnerabilities listed in CVE-2008-3920.