remote IRC servers can execute arbitrary commands
Bug #129771 reported by
StefanPotyra
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
ircii-pana (Debian) |
Fix Released
|
Unknown
|
|||
ircii-pana (Ubuntu) |
Fix Released
|
Medium
|
Kees Cook | ||
Dapper |
Fix Released
|
Medium
|
Kees Cook | ||
Edgy |
Fix Released
|
Medium
|
Kees Cook | ||
Feisty |
Fix Released
|
Medium
|
Kees Cook |
Bug Description
"hook.c in BitchX 1.1-final allows remote IRC servers to execute
arbitrary commands by sending a client certain data containing NICK and
EXEC strings, which exceeds the bounds of a hash table, and injects an
EXEC hook function that receives and executes shell commands." (from CVE-2007-3360)
(Debian-bug: 432120, ubuntu section universe)
Related branches
CVE References
Changed in ircii-pana: | |
status: | Unknown → New |
Changed in ircii-pana: | |
assignee: | nobody → ubuntu-security |
Changed in ircii-pana: | |
status: | New → Confirmed |
status: | New → Confirmed |
status: | New → Confirmed |
Changed in ircii-pana: | |
assignee: | ubuntu-security → keescook |
importance: | Undecided → Medium |
status: | Fix Released → In Progress |
assignee: | nobody → keescook |
importance: | Undecided → Medium |
status: | Confirmed → In Progress |
assignee: | nobody → keescook |
importance: | Undecided → Medium |
status: | Confirmed → In Progress |
assignee: | nobody → keescook |
importance: | Undecided → Medium |
status: | Confirmed → In Progress |
status: | In Progress → Fix Released |
Changed in ircii-pana: | |
status: | New → Fix Released |
To post a comment you must log in.
didn't check exactly about this bug, just saw this while trying to merge the package in the DBTS.
also, the newest version in unstable FTBFS (see bug #129134 for details).