Summary: | net-irc/ngircd: Remote Format String Vulnerability | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Jean-François Brunette (RETIRED) <formula7> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED INVALID | ||
Severity: | major | CC: | net-irc |
Priority: | High | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | All | ||
URL: | http://www.nosystem.com.ar/advisories/advisory-11.txt | ||
Whiteboard: | B1 [ebuild] | ||
Package list: | Runtime testing required: | --- |
Description
Jean-François Brunette (RETIRED)
2005-02-03 08:49:01 UTC
net-irc: please apply patch and bump IDENT support is disabled by default and we don't enable it in our ebuild. So Gentoo's package is not affected by this. I just diff'ed the 0.8.2 source against the new 0.8.3 release and the only change is the inclusion of the named security patch. Still want me to bump? Anyway, it's a flaw in the source that should be fixed, going to bump. net-irc/ngircd-0.8.3 in CVS Thanks Sven ! Not affected -> INVALID |