This bug was fixed in the package kvirc - 4:4.0.0~svn3900+rc2-1ubuntu0.1
---------------
kvirc (4:4.0.0~svn3900+rc2-1ubuntu0.1) lucid-security; urgency=low
* SECURITY UPDATE: Two security issues have been discovered in the DCC
protocol support code of kvirc, a KDE-based next generation IRC client,
which allow the overwriting of local files through directory traversal
and the execution of arbitrary code through a format string attack.
- kubuntu_01_CVE-2010-2451_CVE-2010-2451_DCC_fix.patch
- Patch based on upstream SVN revision 4317.
- CVE-2010-2451, CVE-2010-2452:
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2451
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2452
- LP: #601702
-- Andreas Wenning <[email protected]> Mon, 05 Jul 2010 00:42:47 +0200
** Changed in: kvirc (Ubuntu Lucid)
Status: Fix Committed => Fix Released
** Changed in: kvirc (Ubuntu Karmic)
Status: Fix Committed => Fix Released
--
CVE-2010-2451, CVE-2010-2452 Multiple vulnerabilities in DCC
https://bugs.launchpad.net/bugs/601702
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs