Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 10: 2009-1234 Moderate: BIND Remote Denial Of Service

fedora
Calendar Grey May 28, 2009
Dist Fedora Esm H88
Fedora 9 has updated Eggdrop to fix a serious remote denial of service vulnerability via crafted PRIVMSG commands. Users should upgrade their installations promptly
mod/server.mod/servmsg.c in Eggheads Eggdrop and Windrop 1.6.19 and earlier allows remote attackers to cause a denial of service (crash) via a crafted PRIVMSG that causes an empty...

Summary

Eggdrop is the world's most popular Open Source IRC bot, designed

for flexibility and ease of use. It is extendable with Tcl scripts

and/or C modules, has support for the big five IRC networks and is

able to form botnets, share partylines and userfiles between bots.

Update Information:

mod/server.mod/servmsg.c in Eggheads Eggdrop and Windrop 1.6.19 and earlier allows remote attackers to cause a denial of service (crash) via a crafted PRIVMSG that causes an empty string to trigger a negative string length copy. NOTE: this issue exists because of an incorrect fix for CVE-2007-2807. The current remote denial of service is tracked as CVE-2009-1789.

Change Log

* Tue May 26 2009 Robert Scheck 1.6.19-4 - Added upstream ctcpfix to solve CVE-2009-1789 (#502650) * Mon Feb 23 2009 Robert Scheck 1.6.19-3 - Rebuild for gcc 4.4 and rpm 4.6 * Sat Aug 30 2008 Robert Scheck 1.6.19-2 - Re-diffed eggdrop configuration patch for no fuzz

References


[ 1 ] Bug #502650 - CVE-2009-1789 eggdrop DoS (crash) https://bugzilla.redhat.com/show_bug.cgi?id=502650

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update eggdrop' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
important
Lowest
Low
Medium
High
Critical

Name: eggdrop
Product: Fedora 9
Version: 1.6.19
Release: 4.fc9
Summary: The world's most popular Open Source IRC bot

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here