First published: Tue Oct 29 2019(Updated: )
Bitlbee does not drop extra group privileges correctly in unix.c
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Bitlbee Bitlbee | =3.0.4 | |
debian/bitlbee | 3.6-1.2 3.6-1.3 3.6-1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-1187 is classified as a medium severity vulnerability.
To fix CVE-2012-1187, upgrade Bitlbee to version 3.6-1.4 or later.
CVE-2012-1187 allows local users to gain additional privileges when Bitlbee is running.
Bitlbee version 3.0.4 is affected by CVE-2012-1187.
No, the latest Debian package versions 3.6-1.2 and above do not include CVE-2012-1187.