Bug 428935 (CVE-2008-0285) - CVE-2008-0285 ngircd: Remotely triggered crash
Summary: CVE-2008-0285 ngircd: Remotely triggered crash
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: CVE-2008-0285
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL: http://nvd.nist.gov/nvd.cfm?cvename=C...
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2008-01-16 05:53 UTC by Red Hat Product Security
Modified: 2009-10-23 19:05 UTC (History)
1 user (show)

Fixed In Version: ngircd-0.11.0
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2008-10-24 18:09:49 UTC
Embargoed:


Attachments (Terms of Use)

Description Lubomir Kundrak 2008-01-16 05:53:39 UTC
Common Vulnerabilities and Exposures assigned an identifier CVE-2008-0285 to the following vulnerability:

ngIRCd 0.10.x before 0.10.4 and 0.11.0 before 0.11.0-pre2 allows remote attackers to cause a denial of service (crash) via crafted IRC PART message, which triggers an invalid dereference.

References:

http://arthur.barton.de/cgi-bin/viewcvs.cgi/ngircd/ngircd/src/ngircd/irc-channel.c?r1=1.40&r2=1.41&diff_format=h
http://bugs.gentoo.org/show_bug.cgi?id=204834
http://ngircd.barton.de/doc/ChangeLog

Comment 1 Lubomir Kundrak 2008-01-16 06:04:23 UTC
Not yet in Fedora. Here is the review request: bug #234926

Comment 3 Andreas Thienemann 2008-10-23 09:59:53 UTC
FYI: This bug should be closed for good, the vulnerable version was never available in fedora AFAIK.

Comment 4 Tomas Hoger 2008-10-24 18:09:49 UTC
Agree, this can be closed.  I haven't closed it before as it wasn't clear to me what's the ngircd's review request.  It is closed now, but ngircd only seems to be shipped in EPEL5 and may appear in F10.

Comment 5 Red Hat Bugzilla 2009-10-23 19:05:18 UTC
Reporter changed to security-response-team by request of Jay Turner.


Note You need to log in before you can comment on or make changes to this bug.