Public bug reported:

Howdy,

Atheme made a point release as a flaw was found that allowed an attacker to 
identify as anyone in certain (common) configurations with InspIRCd.

The upstream commit on this can be found on their github[0] repo, there has 
been 
no CVE assigned.


[0]: 
https://github.com/atheme/atheme/commit/de2ba3ca8f6c39b41431d989f3ac66002a487839

** Affects: atheme-services (Ubuntu)
     Importance: Undecided
         Status: New

** Patch added: "atheme-services.ubuntu.debdiff"
   
https://bugs.launchpad.net/bugs/1960097/+attachment/5559239/+files/atheme-services.ubuntu.debdiff

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1960097

Title:
  atheme-services impersonation vulnerability

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/atheme-services/+bug/1960097/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to