PT-2004-1698 · Ircd Ratbox+1 · Ircd-Ratbox+1
Einride
+1
·
Published
2004-06-30
·
Updated
2017-07-11
·
CVE-2004-0605
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
ircd-hybrid versions 7.0.1 and earlier
ircd-ratbox versions 1.5.1 and earlier
ircd-ratbox versions 2.0rc6 and earlier
Description
The issue affects non-registered IRC users, allowing remote attackers to cause a denial of service by repeatedly making requests. These requests are slowly dequeued due to the lack of a rate-limit imposed on the affected software.
Recommendations
For ircd-hybrid versions 7.0.1 and earlier, update to a version that imposes rate limits on non-registered IRC users.
For ircd-ratbox versions 1.5.1 and earlier, update to a version that imposes rate limits on non-registered IRC users.
For ircd-ratbox versions 2.0rc6 and earlier, update to a version that imposes rate limits on non-registered IRC users.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ircd-Hybrid
Ircd-Ratbox