Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 61432 - net-p2p/opendchub-0.7.14 telnet vulnerability
Summary: net-p2p/opendchub-0.7.14 telnet vulnerability
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All All
: High minor (vote)
Assignee: Gentoo Security
URL: http://sourceforge.net/tracker/index....
Whiteboard: B4? [glsa+]
Keywords:
Depends on:
Blocks:
 
Reported: 2004-08-23 14:08 UTC by Jon Hood (RETIRED)
Modified: 2011-10-30 22:39 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Jon Hood (RETIRED) gentoo-dev 2004-08-23 14:08:38 UTC
opendchub-0.7.14 is vulnerable to people logging in to the provided telnet daemon and speaking in chatrooms as any user they desire. Two things to note are:
1) normally this is firewalled
2) you can also set admin_localhost to 1 in the configuration

0.7.14-r1 with the required patch is about to be put into portage and marked stable on x86 (only architecture this is currently available for). I don't know if a GLSA is required for this.

Resources:
http://sourceforge.net/forum/forum.php?thread_id=1111511&forum_id=143363
http://sourceforge.net/tracker/index.php?func=detail&aid=997016&group_id=41830&atid=431659
Comment 1 Jon Hood (RETIRED) gentoo-dev 2004-08-23 14:10:58 UTC
net-p2p/opendchub-0.7.14-r1 now stable on x86 with patch
Comment 2 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2004-08-23 14:18:09 UTC
Security please vote on GLSA and draft if necessary.
Comment 3 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2004-08-27 12:49:11 UTC
**bump**
Security please vote. Previous version were marked x86 only.
**bump**
Comment 4 Kurt Lieber (RETIRED) gentoo-dev 2004-08-27 13:34:39 UTC
I'd say this is fairly low-risk and doesn't need a glsa.
Comment 5 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2004-08-28 15:49:02 UTC
Closing without GLSA.