CVE-2008-3969
published 2008-09-11CVE-2008-3969: Multiple unspecified vulnerabilities in BitlBee before 1.2.3 allow remote attackers to "overwrite" and "hijack" existing accounts via unknown vectors related…
PriorityP420medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
2.41%
82.2th percentile
Multiple unspecified vulnerabilities in BitlBee before 1.2.3 allow remote attackers to "overwrite" and "hijack" existing accounts via unknown vectors related to "inconsistent handling of the USTATUS_IDENTIFIED state." NOTE: this issue exists because of an incomplete fix for CVE-2008-3920.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| bitlbee | bitlbee | < 1.2.3 | 1.2.3 |
| bitlbee | bitlbee | >= 0 < 1.2.3-1 | 1.2.3-1 |
| bitlbee | bitlbee | >= 0 < 1.2.3-1 | 1.2.3-1 |
| bitlbee | bitlbee | >= 0 < 1.2.3-1 | 1.2.3-1 |
| debian | bitlbee | < bitlbee 1.2.3-1 (bookworm) | bitlbee 1.2.3-1 (bookworm) |
| fedoraproject | fedora | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cm46-p4pg-4w4f: Multiple unspecified vulnerabilities in BitlBee before 1
ghsa_unreviewed·2022-05-02·CVSS 7.5
CVE-2008-3969 [HIGH] GHSA-cm46-p4pg-4w4f: Multiple unspecified vulnerabilities in BitlBee before 1
Multiple unspecified vulnerabilities in BitlBee before 1.2.3 allow remote attackers to "overwrite" and "hijack" existing accounts via unknown vectors related to "inconsistent handling of the USTATUS_IDENTIFIED state." NOTE: this issue exists because of an incomplete fix for CVE-2008-3920.
OSV
CVE-2008-3969: Multiple unspecified vulnerabilities in BitlBee before 1
osv·2008-09-11·CVSS 7.5
CVE-2008-3969 [HIGH] CVE-2008-3969: Multiple unspecified vulnerabilities in BitlBee before 1
Multiple unspecified vulnerabilities in BitlBee before 1.2.3 allow remote attackers to "overwrite" and "hijack" existing accounts via unknown vectors related to "inconsistent handling of the USTATUS_IDENTIFIED state." NOTE: this issue exists because of an incomplete fix for CVE-2008-3920.
Debian
CVE-2008-3969: bitlbee - Multiple unspecified vulnerabilities in BitlBee before 1.2.3 allow remote attack...
vendor_debian·2008·CVSS 7.5
CVE-2008-3969 [HIGH] CVE-2008-3969: bitlbee - Multiple unspecified vulnerabilities in BitlBee before 1.2.3 allow remote attack...
Multiple unspecified vulnerabilities in BitlBee before 1.2.3 allow remote attackers to "overwrite" and "hijack" existing accounts via unknown vectors related to "inconsistent handling of the USTATUS_IDENTIFIED state." NOTE: this issue exists because of an incomplete fix for CVE-2008-3920.
Scope: local
bookworm: resolved (fixed in 1.2.3-1)
bullseye: resolved (fixed in 1.2.3-1)
sid: resolved (fixed in 1.2.3-1)
trixie: resolved (fixed in 1.2.3-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/31690http://secunia.com/advisories/31991http://security.gentoo.org/glsa/glsa-200809-14.xmlhttp://www.bitlbee.org/main.php/changelog.htmlhttp://www.bitlbee.org/main.php/news.r.htmlhttp://www.openwall.com/lists/oss-security/2008/09/08/1http://www.openwall.com/lists/oss-security/2008/09/09/11http://www.securityfocus.com/bid/31342https://bugzilla.redhat.com/show_bug.cgi?id=461424https://exchange.xforce.ibmcloud.com/vulnerabilities/45132https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00587.htmlhttp://secunia.com/advisories/31690http://secunia.com/advisories/31991http://security.gentoo.org/glsa/glsa-200809-14.xmlhttp://www.bitlbee.org/main.php/changelog.htmlhttp://www.bitlbee.org/main.php/news.r.htmlhttp://www.openwall.com/lists/oss-security/2008/09/08/1http://www.openwall.com/lists/oss-security/2008/09/09/11http://www.securityfocus.com/bid/31342https://bugzilla.redhat.com/show_bug.cgi?id=461424https://exchange.xforce.ibmcloud.com/vulnerabilities/45132https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00587.html
2008-09-11
Published