CVE-2012-1187: Critical severity bitlbee BitlBee vulnerability
Published Oct 29, 2019
·Updated
Bitlbee does not drop extra group privileges correctly in unix.c
Affected Software
2 affected componentsFixes available
bitlbee BitlBee=3.0.4
debian/bitlbee
3.6-1.23.6-1.33.6-1.53.6-2
Event History
Oct 29, 2019
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
DescriptionWeakness
Feb 18, 2026
Data Sourced
via Debian·01:04 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2012-1187?
CVE-2012-1187 is classified as a medium severity vulnerability.
2
How do I fix CVE-2012-1187?
To fix CVE-2012-1187, upgrade Bitlbee to version 3.6-1.4 or later.
3
What impact does CVE-2012-1187 have on affected systems?
CVE-2012-1187 allows local users to gain additional privileges when Bitlbee is running.
4
Which versions of Bitlbee are affected by CVE-2012-1187?
Bitlbee version 3.0.4 is affected by CVE-2012-1187.
5
Is CVE-2012-1187 present in the latest Debian package for Bitlbee?
No, the latest Debian package versions 3.6-1.2 and above do not include CVE-2012-1187.