Gentoo Archives: gentoo-announce

From: Daniel Ahlberg <aliz@g.o>
To: gentoo-announce@g.o
Subject: GLSA: bitchx (200302-11)
Date: Thu, 20 Feb 2003 18:00:17
Message-Id: 20030220174346.DE3BE5761@mail2.tamperd.net
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - ---------------------------------------------------------------------
5 GENTOO LINUX SECURITY ANNOUNCEMENT 200302-11
6 - - ---------------------------------------------------------------------
7
8 PACKAGE : bitchx
9 SUMMARY : denial of service
10 DATE : 2003-02-20 17:47 UTC
11 EXPLOIT : remote
12
13 - - ---------------------------------------------------------------------
14
15 - From advisory:
16
17 "A denial of service vulnerability exists in BitchX. Sending
18 a malformed RPL_NAMREPLY numeric 353 causes BitchX to segfault."
19
20 Read the full advisory at:
21 http://marc.theaimsgroup.com/?l=bugtraq&m=104554352513997&w=2
22
23 SOLUTION
24
25 It is recommended that all Gentoo Linux users who are running
26 net-irc/bitchx upgrade to bitchx-1.0.19-r4 as follows:
27
28 emerge sync
29 emerge -u bitchx
30 emerge clean
31
32 - - ---------------------------------------------------------------------
33 aliz@g.o - GnuPG key is available at http://cvs.gentoo.org/~aliz
34 - - ---------------------------------------------------------------------
35 -----BEGIN PGP SIGNATURE-----
36 Version: GnuPG v1.2.1 (GNU/Linux)
37
38 iD8DBQE+VRTLfT7nyhUpoZMRAvqiAJ4kel27B+vLN8ZRuxYZGqLvhlrvMACdFB+z
39 6LgjJMmjYP+/EGRH0nGzAmI=
40 =dRwx
41 -----END PGP SIGNATURE-----