First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 66912
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Matthias Geerdsen <vorlon@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 66912 depends on: Show dependency tree
Bug 66912 blocks:
Votes: 0    Show votes for this bug    Vote for this bug

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2004-10-09 12:58 0000
From the changes page:

http://www.gotbnc.com/changes.html
2.8.9

   1. Fixed backspace security flaw (reported by Yak)
...

_______________________________
http://secunia.com/advisories/12770/

Secunia Advisory:	SA12770	Print Advisory  
Release Date:	2004-10-09

Critical: Moderately critical
Impact:	Unknown
Where:	From remote
Solution Status:	Vendor Patch

Software:	BNC IRC proxy 2.x

Description:
Yak has reported a vulnerability with an unknown impact in BNC IRC proxy.

The vulnerability is reportedly caused due to an unspecified backspace security flaw.

Solution: Update to version 2.8.9.
http://www.gotbnc.com/download.html

Provided and/or discovered by:
Yak

_____________________________

net-irc, pls bump to 2.8.9

------- Comment #1 From Sven Wegener 2004-10-09 13:29:48 0000 -------
Commited to CVS and marked stable on x86.

------- Comment #2 From Matthias Geerdsen 2004-10-09 13:41:07 0000 -------
Thanks for the quick reaction Sven.

arches, pls test and mark 2.8.9 stable

current KEYWORDS="x86 ~ppc ~sparc ~alpha ~arm"
target KEYWORDS="x86 ppc sparc alpha arm"


------- Comment #3 From Jason Wever (RETIRED) 2004-10-09 14:16:48 0000 -------
Stable on sparc.

------- Comment #4 From Pieter Van den Abeele 2004-10-09 14:36:01 0000 -------
stable on ppc

------- Comment #5 From Bryan Østergaard (RETIRED) 2004-10-09 15:56:13 0000 -------
Stable on alpha.

------- Comment #6 From Matthias Geerdsen 2004-10-10 02:42:21 0000 -------
Sent mail upstrem asking for more information.
Changed to [glsa?], but should wait for a reply.

------- Comment #7 From Matthias Geerdsen 2004-10-11 05:03:11 0000 -------
Got back the following information:

bnc 2.6.4 introduced a new input parsing routine.  The function sbuf_getmsg
would process the received data into lines.  Part of this function would
interpret the backspace character 008 and step backwards on the input
processing.  This would allow a malicious user to send backspaces to clear
the true credentials, and then insert fake creditials to gain access to low
security bots or weak irc scripts that was on the client end of a BNC.

------- Comment #8 From Matthias Geerdsen 2004-10-11 05:25:37 0000 -------
also http://securitytracker.com/id?1011583 

Description:  A vulnerability was reported in BNC. A remote user can send arbitrary commands to a bot running BNC.

The vendor reported that the software contains a flaw in the processing of the backspace character (ASCII 8). A remote user can send data that includes backspace characters to delete and replace data sent to the BNC bot to issue commands with arbitrary authentication credentials.

------- Comment #9 From Thierry Carrez (RETIRED) 2004-10-11 06:16:44 0000 -------
So it's a B3.
Please vote on GLSA need...

I suppose we should issue one ?

------- Comment #10 From Sven Wegener 2004-10-11 06:56:14 0000 -------
Yep, qualifies for a GLSA in my opinion.

------- Comment #11 From Matthias Geerdsen 2004-10-12 01:53:54 0000 -------
agreed, should issue a GLSA

------- Comment #12 From Thierry Carrez (RETIRED) 2004-10-12 04:41:11 0000 -------
ready for a GLSA

------- Comment #13 From Thierry Carrez (RETIRED) 2004-10-15 05:13:48 0000 -------
GLSA 200410-13
arm should mark stable to benefit from GLSA

First Last Prev Next    No search results available      Search page      Enter new bug