Bug 428935 (CVE-2008-0285)

Summary: CVE-2008-0285 ngircd: Remotely triggered crash
Product: [Other] Security Response Reporter: Red Hat Product Security <security-response-team>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED CURRENTRELEASE QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: andreas
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
URL: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-0285
Whiteboard:
Fixed In Version: ngircd-0.11.0 Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2008-10-24 18:09:49 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Lubomir Kundrak 2008-01-16 05:53:39 UTC
Common Vulnerabilities and Exposures assigned an identifier CVE-2008-0285 to the following vulnerability:

ngIRCd 0.10.x before 0.10.4 and 0.11.0 before 0.11.0-pre2 allows remote attackers to cause a denial of service (crash) via crafted IRC PART message, which triggers an invalid dereference.

References:

http://arthur.barton.de/cgi-bin/viewcvs.cgi/ngircd/ngircd/src/ngircd/irc-channel.c?r1=1.40&r2=1.41&diff_format=h
http://bugs.gentoo.org/show_bug.cgi?id=204834
http://ngircd.barton.de/doc/ChangeLog

Comment 1 Lubomir Kundrak 2008-01-16 06:04:23 UTC
Not yet in Fedora. Here is the review request: bug #234926

Comment 3 Andreas Thienemann 2008-10-23 09:59:53 UTC
FYI: This bug should be closed for good, the vulnerable version was never available in fedora AFAIK.

Comment 4 Tomas Hoger 2008-10-24 18:09:49 UTC
Agree, this can be closed.  I haven't closed it before as it wasn't clear to me what's the ngircd's review request.  It is closed now, but ngircd only seems to be shipped in EPEL5 and may appear in F10.

Comment 5 Red Hat Bugzilla 2009-10-23 19:05:18 UTC
Reporter changed to security-response-team by request of Jay Turner.