Release date:
Updated on:
Affected Systems:
Gentoo atheme
Description:
--------------------------------------------------------------------------------
Cve id: CVE-2012-1576
Atheme is a portable, secure, open-source, and modular IRC service set. Gentoo is a free operating system based on Linux or FreeBSD. It can automatically optimize and customize almost any application or demand.
Gentoo released the atheme update and fixed a security vulnerability, account. the "myuser_delete ()" function in c does not correctly remove CertFP entries after deleting the user account. After successful exploitation, it can bypass certain security restrictions, cause denial of service, and serve the Atheme IRC user account.
<* Source: vendor
Link: http://secunia.com/advisories/50704/
Http://www.gentoo.org/security/en/glsa/glsa-201209-09.xml
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Gentoo
------
Gentoo has released a Security Bulletin (glsa-201209-09) and patches for this:
Glsa-201209-09: Gentoo Linux Security Advisory
Link: http://www.gentoo.org/security/en/glsa/glsa-201209-09.xml