Gentoo Archives: gentoo-announce

From: Kurt Lieber <klieber@g.o>
To: gentoo-announce@l.g.o
Cc: bugtraq@×××××××××××××.com, full-disclosure@××××××××××××.com, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200404-15 ] XChat 2.0.x SOCKS5 Vulnerability
Date: Mon, 19 Apr 2004 09:21:41
Message-Id: 20040419091636.GX16487@mail.lieber.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 200404-15
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Low
8 Title: XChat 2.0.x SOCKS5 Vulnerability
9
10 Date: April 19, 2004
11 Bugs: #46856
12 ID: 200404-15
13
14 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
15
16 Synopsis
17 ========
18
19 XChat is vulnerable to a stack overflow that may allow a remote
20 attacker to run arbitrary code.
21
22 Background
23 ==========
24
25 XChat is a multiplatform IRC client.
26
27 Affected packages
28 =================
29
30 -------------------------------------------------------------------
31 Package / Vulnerable / Unaffected
32 -------------------------------------------------------------------
33 net-irc/xchat < 2.0.8-r1 >= 2.0.8-r1
34
35 Description
36 ===========
37
38 The SOCKS 5 proxy code in XChat is vulnerable to a remote exploit.
39 Users would have to be using XChat through a SOCKS 5 server, enable
40 SOCKS 5 traversal which is disabled by default and also connect to an
41 attacker's custom proxy server.
42
43 Impact
44 ======
45
46 This vulnerability may allow an attacker to run arbitrary code within
47 the context of the user ID of the XChat client.
48
49 Workaround
50 ==========
51
52 A workaround is not currently known for this issue. All users are
53 advised to upgrade to the latest version of the affected package.
54
55 Resolution
56 ==========
57
58 All XChat users should upgrade to the latest stable version:
59
60 # emerge sync
61
62 # emerge -pv ">=net-irc/xchat-2.0.8-r1"
63 # emerge ">=net-irc/xchat-2.0.8-r1"
64
65 Note that users of the gtk1 version of xchat (1.8.*) should upgrade to
66 xchat-1.8.11-r1:
67
68 # emerge sync
69
70 # emerge -pv "=net-irc/xchat-1.8.11-r1"
71 # emerge "=net-irc/xchat-1.8.11-r1"
72
73 References
74 ==========
75
76 [ 1 ] http://mail.nl.linux.org/xchat-announce/2004-04/msg00000.html
77
78 Availability
79 ============
80
81 This GLSA and any updates to it are available for viewing at
82 the Gentoo Security Website:
83
84 http://security.gentoo.org/glsa/glsa-200404-15.xml
85
86 Concerns?
87 =========
88
89 Security is a primary focus of Gentoo Linux and ensuring the
90 confidentiality and security of our users machines is of utmost
91 importance to us. Any security concerns should be addressed to
92 security@g.o or alternatively, you may file a bug at
93 http://bugs.gentoo.org.
94
95 License
96 =======
97
98 Copyright 2004 Gentoo Technologies, Inc; referenced text
99 belongs to its owner(s).
100
101 The contents of this document are licensed under the
102 Creative Commons - Attribution / Share Alike license.
103
104 http://creativecommons.org/licenses/by-sa/1.0