PT-2013-5655 · Ngircd · Ngircd

Publicado

2013-08-30

·

Atualizado

2013-10-02

·

CVE-2013-5580

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions ngIRCd versions 18 through 20.2
Description The issue is related to the handling of return codes for the Handle Write function in the Conn StartLogin and cb Read Resolver Result functions. When the NoticeAuth configuration option is enabled, remote attackers can cause a denial of service, leading to an assertion failure and server crash. This is related to a "notice auth" message not being sent to a new client.
Recommendations For ngIRCd versions 18 through 20.2, consider disabling the NoticeAuth configuration option as a temporary workaround to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-5580
MGASA-2013-0265

Produtos afetados

Ngircd