This bug was fixed in the package kvirc - 4:4.0.0~svn3900+rc2-1ubuntu0.2

---------------
kvirc (4:4.0.0~svn3900+rc2-1ubuntu0.2) lucid-security; urgency=low

  * SECURITY UPDATE: The IRC Protocol component in KVIrc 3.x and 4.x before
    r4693 does not properly handle \ (backslash) characters, which allows
    remote authenticated users to execute arbitrary CTCP commands via vectors
    involving \r and \40 sequences, a different vulnerability than CVE-2010-2451
    and CVE-2010-2452.
    - 33_upstream_security_#858.patch
      - Patch based on upstream SVN revision 4693.
    - CVE-2010-2785:
      - http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2785
    - LP: #612682
 -- Nathan Handler <nhand...@ubuntu.com>   Sat, 12 Mar 2011 20:00:18 -0600

** Changed in: kvirc (Ubuntu Lucid)
       Status: Fix Committed => Fix Released

** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2010-2451

** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2010-2452

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/612682

Title:
  KVIrc security release 4.0.2 avaible

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to