Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Thommey

#51489de 53,632
4.3CVSS total
Vulnerabilidades · 1
PT-2009-4258
4.3
2009-05-26
Eggdrop · Eggdrop · CVE-2009-1789
Name of the Vulnerable Software and Affected Versions: Eggdrop versions 1.6.19 and earlier Windrop versions 1.6.19 and earlier Description: The issue allows remote attackers to cause a denial of service, resulting in a crash, by sending a crafted PRIVMSG that triggers a negative string length copy due to an empty string. This problem exists because of an incorrect fix for a previous issue. Recommendations: For Eggdrop versions 1.6.19 and earlier, consider updating to a version that correctly addresses the issue. For Windrop versions 1.6.19 and earlier, consider updating to a version that correctly addresses the issue. As a temporary workaround, consider restricting access to the `servmsg.c` module in `mod/server.mod` to minimize the risk of exploitation.