GLSA Advocate
Joined: 12 May 2004 Posts: 2663
|
Posted: Fri May 09, 2008 4:26 pm Post subject: [ GLSA 200805-08 ] InspIRCd: Denial of Service |
|
|
Gentoo Linux Security Advisory
Title: InspIRCd: Denial of Service (GLSA 200805-08)
Severity: normal
Exploitable: remote
Date: May 09, 2008
Bug(s): #215704
ID: 200805-08
Synopsis
A buffer overflow in InspIRCd allows remote attackers to cause a Denial of Service.
Background
InspIRCd (Inspire IRCd) is a modular C++ IRC daemon.
Affected Packages
Package: net-irc/inspircd
Vulnerable: < 1.1.19
Unaffected: >= 1.1.19
Architectures: All supported architectures
Description
The "namesx" and "uhnames" modules do not properly validate network input, leading to a buffer overflow.
Impact
A remote attacker can send specially crafted IRC commands to the server, causing a Denial of Service.
Workaround
Unload the "uhnames" module in the InspIRCd configuration.
Resolution
All InspIRCd users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=net-irc/inspircd-1.1.19" |
References
CVE-2008-1925 |
|