Summary: | <net-irc/kvirc-4.0_pre4317: DCC Directory Traversal and Multiple Format String Vulnerabilities (CVE-2010-{2451,2452}) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Samuli Suominen (RETIRED) <ssuominen> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | major | CC: | arfrever, net-irc |
Priority: | High | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | B1 [glsa] | ||
Package list: | Runtime testing required: | --- | |
Bug Depends on: | 278423 | ||
Bug Blocks: |
Description
Samuli Suominen (RETIRED)
![]() Security vulnerability was fixed in r4317. r4227 introduced build failure with USE="dcc_video -kde", which was fixed in r4616. Stabilize net-irc/kvirc-4.1_pre4624. x86 stable amd64 done CVE-2010-2451 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2451): Multiple format string vulnerabilities in the DCC functionality in KVIrc 3.4 and 4.0 have unspecified impact and remote attack vectors. CVE-2010-2452 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2452): Directory traversal vulnerability in the DCC functionality in KVIrc 3.4 and 4.0 allows remote attackers to overwrite arbitrary files via unknown vectors. GLSA request filed. This issue was resolved and addressed in GLSA 201402-20 at http://security.gentoo.org/glsa/glsa-201402-20.xml by GLSA coordinator Chris Reffett (creffett). |