Public bug reported: Howdy,
Atheme made a point release as a flaw was found that allowed an attacker to identify as anyone in certain (common) configurations with InspIRCd. The upstream commit on this can be found on their github[0] repo, there has been no CVE assigned. [0]: https://github.com/atheme/atheme/commit/de2ba3ca8f6c39b41431d989f3ac66002a487839 ** Affects: atheme-services (Ubuntu) Importance: Undecided Status: New ** Patch added: "atheme-services.ubuntu.debdiff" https://bugs.launchpad.net/bugs/1960097/+attachment/5559239/+files/atheme-services.ubuntu.debdiff -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1960097 Title: atheme-services impersonation vulnerability To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/atheme-services/+bug/1960097/+subscriptions -- ubuntu-bugs mailing list [email protected] https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
