Debian Security Advisory: New version of xchat released (update)

Aug 30, 2000, 19:58 (0 Talkback[s])

Date: Wed, 30 Aug 2000 07:40:39 -0700
From: debian-security-announce@LISTS.DEBIAN.ORG
Subject: [SECURITY] New version of xchat released (update)

Debian Security Advisory                                        Wichert Akkerman 
August 30, 2000

Package        : xchat
Problem type   : remote exploit
Debian-specific: no
The version of X-Chat that was distributed with Debian GNU/Linux 2.2 has a vulnerability in the URL handling code: when a user clicks on a URL X-Chat will start netscape to view its target. However it did not check the URL for shell metacharacters, and this could be abused to trick xchat into executing arbitraty commands.

This has been fixed in version 1.4.3-0.1, and we recommend you upgrade your xchat package(s) immediately.

Update: the powerpc packages mentioned in the first release of this advisory were linked with a version of libgtk that is not available in Debian GNU/Linux 2.2. They have been recompiled with the correct version and reuploaded.

wget url
        will fetch the file for you
dpkg -i file.deb
        will install the referenced file.
Debian GNU/Linux 2.2 alias potato

Potato was released for the alpha, arm, i386, m68k, powerpc and sparc architectures.

