Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

XChat SOCKS 5 Remote Buffer Overrun Vulnerability

Solution:
Red Hat has released an advisory (RHSA-2004:177-01) and fixes to address this issue in Red Hat Linux 9. Red Hat Linux users are advised to see the referenced advisory for further details regarding obtaining and applying appropriate fixes.

Gentoo has released updates for this issue, which may be applied with the following commands:
# emerge sync
# emerge -pv "=net-irc/xchat-1.8.11-r1"
# emerge "=net-irc/xchat-1.8.11-r1"

Debian has released advisory DSA 493-1 with patches dealing with this issue.

Mandrake has released advisory MDKSA-2004:036 as well as fixes dealing with this issue.

Netwosix has realeased an advisory (LNSA-#2004-0014) and fixes for this issue. To obtain fixed packages, users should execute the following commands:
# cd /usr/ports/graphics/xchat/
# rm nepote
# wget http://download.netwosix.org/0014/nepote
# sh nepote

The vendor has also released a source code patch.

Red Hat has released a Fedora legacy advisory (FLSA:1549) to address this issue in xchat. This advisory fixes the issue in Red Hat Linux 7.3 running on the i386 architecture. Please see the referenced advisory for more details and information about obtaining fixes.

Red Hat has released advisory RHSA-2004:297-09 and fixes to address this issue on Red Hat Linux Enterprise platforms. Customers who are affected by this issue are advised to apply the appropriate updates. Customers subscribed to the Red Hat Network may apply the appropriate fixes using the Red Hat Update Agent (up2date). Please see referenced advisory for additional information.

Fedora Legacy has released security advisory FLSA:123013 addressing this issue for Fedora Core 1 and Core 2. Users are advised to see the referenced advisory for details on obtaining and applying the appropriate updates.


RedHat xchat-1.8.11-7.i386.rpm

X-Chat X-Chat 1.8.9

X-Chat X-Chat 2.0.1

X-Chat X-Chat 2.0.4

X-Chat X-Chat 2.0.5

X-Chat X-Chat 2.0.6

X-Chat X-Chat 2.0.7

X-Chat X-Chat 2.0.8







 

Privacy Statement
Copyright 2008, SecurityFocus