openSUSE Security Update : atheme (openSUSE-2016-590)
Medium Nessus Plugin ID 91207
SynopsisThe remote openSUSE host is missing a security update.
DescriptionThis update for atheme fixes the following issues :
- CVE-2016-4478: Under certain circumstances, a remote attacker could cause denial of service due to a buffer overflow in the XMLRPC response encoding code (boo#978170)
- CVE-2014-9773: Remote attacker could change Atheme's behavior by registering/dropping certain accounts/nicks (boo#978170)
The version update to 7.2.6 also contains a number of upstream fixes.
SolutionUpdate the affected atheme packages.