Atheme IRC Services: Denial of Service
1.
Gentoo Linux Security Advisory
Version Information
| Advisory Reference |
GLSA 201209-09 / atheme |
| Release Date |
September 25, 2012 |
| Latest Revision |
September 25, 2012: 1 |
| Impact |
normal |
| Exploitable |
remote |
| Package |
Vulnerable versions |
Unaffected versions |
Architecture(s) |
| net-irc/atheme-services |
<
6.0.10 |
>=
6.0.10 |
All supported architectures
|
Related bugreports:
#409103
Synopsis
A vulnerability has been found in Atheme which may lead to Denial
of Service or a bypass of security restrictions.
2.
Impact Information
Background
Atheme is a portable and secure set of open-source and modular IRC
services. CertFP is certificate fingerprinting used to authenticate users
to nicknames.
Description
The “myuser_delete()” function in account.c does not properly remove
CertFP entries when deleting user accounts.
Impact
A remote authenticated attacker may be able to cause a Denial of Service
condition or gain access to an Atheme IRC Services user account.
3.
Resolution Information
Workaround
There is no known workaround at this time.
Resolution
All Atheme users should upgrade to the latest version:
Code Listing 3.1: Resolution |
# emerge --sync
# emerge --ask --oneshot --verbose ">=net-irc/atheme-services-6.0.10"
|
4.
References
|