Home > Security > Advisories

Advisories

Mandriva Advisories

Package name BitchX
Date June 17th, 2003
Advisory ID MDKSA-2003:069
Affected versions 9.0, 9.1
Synopsis Updated BitchX packages fix DoS vulnerability

Problem Description

A Denial Of Service (DoS) vulnerability was discovered in BitchX that
would allow a remote attacker to crash BitchX by changing certain
channel modes. This vulnerability has been fixed in CVS and patched
in the released updates.

Updated Packages

Mandrakelinux 9.0

 f7a5912371b9448aaac7dd07c07228db  9.0/RPMS/BitchX-1.0-0.c19.3.1mdk.i586.rpm
eccf1c1bc8a462301a6b2ef5e28c6bb1  9.0/SRPMS/BitchX-1.0-0.c19.3.1mdk.src.rpm

Mandrakelinux 9.1

 53da858527f6a86605cd6f174d755b9e  9.1/RPMS/BitchX-1.0-0.c19.4.1mdk.i586.rpm
c6ab39e1df8edf246cc00eef76079bfe  9.1/SRPMS/BitchX-1.0-0.c19.4.1mdk.src.rpm

Mandrakelinux 9.1/PPC

 bea7910e9e469719de2f5add64c82b16  ppc/9.1/RPMS/BitchX-1.0-0.c19.4.1mdk.ppc.rpm
c6ab39e1df8edf246cc00eef76079bfe  ppc/9.1/SRPMS/BitchX-1.0-0.c19.4.1mdk.src.rpm

References

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-0334
http://marc.theaimsgroup.com/?l=bugtraq&m=104766521328322&w=2
http://www.securityfocus.com/archive/1/321093

Upgrade

To upgrade automatically, use MandrivaUpdate.


Verification

Please verify the update prior to upgrading to ensure the integrity of the downloaded package. You can do this with the command :

                rpm --checksig package.rpm
                

You can get the GPG public key of the Mandriva Security Team to verify the GPG signature of each RPM.

If you use MandrivaUpdate, the verification of md5 checksum and GPG signature is performed automatically for you.