CVE-2011-5129

Publication date 30 August 2012

Last updated 24 July 2024


Ubuntu priority

Heap-based buffer overflow in XChat 2.8.9 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long response string.

Read the notes from the security team

Status

Package Ubuntu Release Status
xchat 12.04 LTS precise
Not affected
11.10 oneiric
Not affected
11.04 natty
Not affected
10.04 LTS lucid
Not affected
8.04 LTS hardy
Not affected
xchat-gnome 12.04 LTS precise
Not affected
11.10 oneiric
Not affected
11.04 natty
Not affected
10.04 LTS lucid
Not affected
8.04 LTS hardy Ignored end of life

Notes


tyhicks

According to the exploit, specific to xchat in KDE Per Novell bugzilla, requires malicious IRC server Fix not available, so I'm not sure if it affects xchat-gnome at this time


mdeslaur

Not a security issue, see details in redhat bug.