PublicDate: 2008-09-11 01:13:00 UTC Candidate: CVE-2008-3969 References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3969 Description: Multiple unspecified vulnerabilities in BitlBee before 1.2.3 allow remote attackers to "overwrite" and "hijack" existing accounts via unknown vectors related to "inconsistent handling of the USTATUS_IDENTIFIED state." NOTE: this issue exists because of an incomplete fix for CVE-2008-3920. Ubuntu-Description: Notes: Bugs: Priority: low Discovered-by: Assigned-to: CVSS: Patches_bitlbee: upstream_bitlbee: released (1.2.3-1) dapper_bitlbee: ignored (reached end-of-life) feisty_bitlbee: needed (reached end-of-life) gutsy_bitlbee: needed (reached end-of-life) hardy_bitlbee: ignored (reached end-of-life) intrepid_bitlbee: not-affected (1.2.3-1) jaunty_bitlbee: not-affected (1.2.3-1) karmic_bitlbee: not-affected (1.2.3-1) lucid_bitlbee: not-affected (1.2.3-1) maverick_bitlbee: not-affected (1.2.3-1) natty_bitlbee: not-affected (1.2.3-1) oneiric_bitlbee: not-affected (1.2.3-1) devel_bitlbee: not-affected (1.2.3-1)