CVE-2008-3969: Medium severity bitlbee vulnerability
Description of problem: Bitlbee 1.2.3 was released, see the following changelog:
Version 1.2.3: - Fixed one more flaw similar to the previous hijacking bug, caused by incon- sistent handling of the USTATUSIDENTIFIED state. All code touching these variables was reviewed and should be correct now.
Finished 7 Sep 2008
Version-Release number of selected component (if applicable): bitlbee-1.2.2-1
Actual results: bitlbee-1.2.2-1
Expected results: bitlbee-1.2.3-1 ;-)
Other sources
Multiple unspecified vulnerabilities in BitlBee before 1.2.3 allow remote attackers to "overwrite" and "hijack" existing accounts via unknown vectors related to "inconsistent handling of the USTATUSIDENTIFIED state." NOTE: this issue exists because of an incomplete fix for CVE-2008-3920.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-3969?
CVE-2008-3969 is categorized as a moderate severity vulnerability affecting Bitlbee 1.2.3.
How do I fix CVE-2008-3969?
To fix CVE-2008-3969, upgrade to Bitlbee version 1.2.4 or later.
What versions are affected by CVE-2008-3969?
CVE-2008-3969 affects Bitlbee version 1.2.3 and earlier releases.
What type of vulnerability is CVE-2008-3969?
CVE-2008-3969 is a vulnerability that involves improper handling of user status, which could lead to information disclosure.
Is there a workaround for CVE-2008-3969?
A workaround for CVE-2008-3969 is to restrict the use of the affected version until an upgrade can be performed.