Vulnerability Name: | CVE-2008-3969 (CCN-45132) | ||||||||
Assigned: | 2008-09-10 | ||||||||
Published: | 2008-09-10 | ||||||||
Updated: | 2020-07-14 | ||||||||
Summary: | Multiple unspecified vulnerabilities in BitlBee before 1.2.3 allow remote attackers to "overwrite" and "hijack" existing accounts via unknown vectors related to "inconsistent handling of the USTATUS_IDENTIFIED state." Note: this issue exists because of an incomplete fix for CVE-2008-3920. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-noinfo | ||||||||
Vulnerability Consequences: | Bypass Security | ||||||||
References: | Source: CCN Type: BitlBee Web site Download Source: MITRE Type: CNA CVE-2008-3969 Source: SECUNIA Type: Third Party Advisory 31690 Source: SECUNIA Type: Third Party Advisory 31991 Source: GENTOO Type: Third Party Advisory GLSA-200809-14 Source: CCN Type: BitlBee Changelog Version 1.2.3 (released 2008-09-07) hilights Source: CONFIRM Type: Release Notes, Vendor Advisory http://www.bitlbee.org/main.php/changelog.html Source: CCN Type: BitlBee News, 2008-09-07 14:24 UTC BitlBee 1.2.3, unfortunately another important bugfix Source: CONFIRM Type: Release Notes, Vendor Advisory http://www.bitlbee.org/main.php/news.r.html Source: CCN Type: GLSA-200809-14 BitlBee: Security bypass Source: CCN Type: oss-security Mailing List, Mon, 8 Sep 2008 09:36:08 +0200 Re: CVE request for bitlbee Source: MLIST Type: Mailing List, Third Party Advisory [oss-security] 20080908 Re: CVE request for bitlbee Source: CCN Type: oss-security Mailing List, Tue, 9 Sep 2008 10:39:37 -0400 (EDT) Re: CVE request for bitlbee Source: MLIST Type: Mailing List, Third Party Advisory [oss-security] 20080909 Re: CVE request for bitlbee Source: BID Type: Third Party Advisory, VDB Entry 31342 Source: CCN Type: BID-31342 BitlBee Unspecified Security Bypass Variant Vulnerability Source: CONFIRM Type: Issue Tracking, Third Party Advisory https://bugzilla.redhat.com/show_bug.cgi?id=461424 Source: XF Type: Third Party Advisory, VDB Entry bitlbee-multiple-unspecified-security-bypass(45132) Source: XF Type: UNKNOWN bitlbee-multiple-unspecified-security-bypass(45132) Source: FEDORA Type: Third Party Advisory FEDORA-2008-7761 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: ![]() | ||||||||
BACK |