CVE Vulnerabilities

CVE-2008-3969

Published: Sep 11, 2008 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

Multiple unspecified vulnerabilities in BitlBee before 1.2.3 allow remote attackers to overwrite and hijack existing accounts via unknown vectors related to inconsistent handling of the USTATUS_IDENTIFIED state. NOTE: this issue exists because of an incomplete fix for CVE-2008-3920.

Affected Software

NameVendorStart VersionEnd Version
BitlbeeBitlbee*1.2.3 (excluding)
BitlbeeUbuntudapper*
BitlbeeUbuntufeisty*
BitlbeeUbuntugutsy*
BitlbeeUbuntuhardy*
BitlbeeUbuntuupstream*

References