CVE Vulnerabilities

CVE-2008-3969

Published: Sep 11, 2008 | Modified: Jul 14, 2020
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
LOW

Multiple unspecified vulnerabilities in BitlBee before 1.2.3 allow remote attackers to overwrite and hijack existing accounts via unknown vectors related to inconsistent handling of the USTATUS_IDENTIFIED state. NOTE: this issue exists because of an incomplete fix for CVE-2008-3920.

Affected Software

Name Vendor Start Version End Version
Bitlbee Bitlbee * 1.2.3 (excluding)
Bitlbee Ubuntu dapper *
Bitlbee Ubuntu feisty *
Bitlbee Ubuntu gutsy *
Bitlbee Ubuntu hardy *
Bitlbee Ubuntu upstream *

References