Debian Security Advisory DSA-2078-1                               Moritz Muehlenhoff
July 31, 2010               
Package        : kvirc
Vulnerability  : programming error
Problem type   : remote
Debian-specific: no
CVE Id(s)      : CVE-2010-2785

It was discovered that incorrect parsing of CTCP commands in kvirc, a 
KDE-based IRC client, could lead to the execution of arbitrary IRC 
commands against other users.

For the stable distribution (lenny), this problem has been fixed in
version 2:3.4.0-6.

For the unstable distribution (sid), this problem has been fixed in
version 4:4.0.0-3.

We recommend that you upgrade your kvirc package.

Upgrade instructions
wget url
        will fetch the file for you
dpkg -i file.deb
        will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
        will update the internal database
apt-get upgrade
        will install corrected packages

You may use an automated update by adding the resources from the
footer to the proper configuration.

Debian GNU/Linux 5.0 alias lenny
Stable updates are available for alpha, amd64, arm, armel, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc.

