A stack-based buffer overflow in mod/server.mod/servrmsg.c, which might allow user-assisted, remote IRC servers to execute arbitrary code via a long private message, was originally found in Eggdrop 1.6.18, and possibly earlier versions (CVE-2007-2807).Thomas Sader reported, the original fix, fixing the issue was incomplete (introduced another flaw). References: http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/68341 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=528778 Upstream report: http://www.eggheads.org/downloads/ Proposed patch (against latest Eggdrop version): http://www.eggheads.org/redirect.php?url=ftp://ftp.eggheads.org/pub/eggdrop/patches/official/1.6/eggdrop1.6.19%2Bctcpfix.patch.gz
*** This bug has been marked as a duplicate of bug 502650 ***