Description: | Description: The remote host is missing an update to irssi announced via advisory USN-929-2.
Details follow:
USN-929-1 fixed vulnerabilities in irssi. The upstream changes introduced a regression when using irssi with SSL and an IRC proxy. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that irssi did not perform certificate host validation when using SSL connections. An attacker could exploit this to perform a man in the middle attack to view sensitive information or alter encrypted communications. (CVE-2010-1155) Aurelien Delaitre discovered that irssi could be made to dereference a NULL pointer when a user left the channel. A remote attacker could cause a denial of service via application crash. (CVE-2010-1156) This update also adds SSLv3 and TLSv1 support, while disabling the old, insecure SSLv2 protocol.
Solution: The problem can be corrected by upgrading your system to the following package versions:
Ubuntu 8.04 LTS: irssi 0.8.12-3ubuntu3.3
Ubuntu 8.10: irssi 0.8.12-4ubuntu2.3
Ubuntu 9.04: irssi 0.8.12-6ubuntu1.3
Ubuntu 9.10: irssi 0.8.14-1ubuntu1.2
After a standard system upgrade you need to restart irssi to effect the necessary changes.
http://www.securityspace.com/smysecure/catid.html?in=USN-929-2
Risk factor : High
CVSS Score: 6.8
|