Summary
The remote host is missing updates announced in
advisory GLSA 201201-18.
Solution
All bip users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose '>=net-irc/bip-0.8.8-r1'
NOTE: The CVE-2010-3071 flaw was already corrected in an earlier version of bip and is included in this advisory for completeness.
http://www.securityspace.com/smysecure/catid.html?in=GLSA%20201201-18 http://bugs.gentoo.org/show_bug.cgi?id=336321
http://bugs.gentoo.org/show_bug.cgi?id=400599
Insight
Multiple vulnerabilities in bip might allow remote unauthenticated attackers to cause a Denial of Service or possibly execute arbitrary code.
Severity
Classification
-
CVE CVE-2010-3071, CVE-2012-0806 -
CVSS Base Score: 6.5
AV:N/AC:L/Au:S/C:P/I:P/A:P
Related Vulnerabilities