PT-2013-5655 · Ngircd · Ngircd

Published

2013-08-30

·

Updated

2013-10-02

·

CVE-2013-5580

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions ngIRCd versions 18 through 20.2
Description The issue is related to the handling of return codes for the Handle Write function in the Conn StartLogin and cb Read Resolver Result functions. When the NoticeAuth configuration option is enabled, remote attackers can cause a denial of service, leading to an assertion failure and server crash. This is related to a "notice auth" message not being sent to a new client.
Recommendations For ngIRCd versions 18 through 20.2, consider disabling the NoticeAuth configuration option as a temporary workaround to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-5580
MGASA-2013-0265

Affected Products

Ngircd