Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Several vulnerabilities have been discovered in eggdrop, an advanced IRC robot. The Common Vulnerabilities and Exposures project identifies the following problems: . - ------------------------------------------------------------------------ Debian Security Advisory DSA-1826-1
mod/server.mod/servmsg.c in Eggheads Eggdrop and Windrop 1.6.19 and earlier allows remote attackers to cause a denial of service (crash) via a crafted PRIVMSG that causes an empty string to trigger a negative string length copy. NOTE: this issue exists because of an incorrect fix for CVE-2007-2807. The current remote denial of service is tracked as CVE-2009-1789.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2009-5568 2009-05-28 07:01:45 -------------------------------------------------------------------------------- Name : eggdrop Product : Fedora 9 Version : 1.6.19 Release : 4.fc9 URL : http://www.eggheads.org/ Summary : The world's most popular Open Source IRC bot Description : Eggdrop is the world's most popular Open Source IRC bot, designed for flexibility and ease of use. It is extendable with Tcl scripts and/or C modules, has support for the big five IRC networks and is able to form botnets, share partylines and userfiles between bots. -------------------------------------------------------------------------------- Update Information: mod/server.mod/servmsg.c in Eggheads Eggdrop and Windrop 1.6.19 and earlier allows remote attackers to cause a denial of service (crash) via a crafted PRIVMSG that causes an empty string to trigger a negative string length copy. NOTE: this issue exists because of an incorrect fix for CVE-2007-2807. The current remote denial of service is tracked as CVE-2009-1789. -------------------------------------------------------------------------------- ChangeLog: * Tue May 26 2009 Robert Scheck 1.6.19-4 - Added upstream ctcpfix to solve CVE-2009-1789 (#502650) * Mon Feb 23 2009 Robert Scheck 1.6.19-3 - Rebuild for gcc 4.4 and rpm 4.6 * Sat Aug 30 2008 Robert Scheck 1.6.19-2 - Re-diffed eggdrop configuration patch for no fuzz -------------------------------------------------------------------------------- References: [ 1 ] Bug #502650 - CVE-2009-1789 eggdrop DoS (crash) https://bugzilla.redhat.com/show_bug.cgi?id=502650 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update eggdrop' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailing list
The unaffected ebuild, as reported in the original version of this Security Advisory, did not properly address all vulnerabilities. All Eggdrop users should upgrade to net-irc/eggdrop-1.6.18-r3. [More...]. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory [ERRATA UPDATE] GLSA 200709-07:02 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Eggdrop: Buffer overflow Date: September 15, 2007 Updated: September 26, 2007 Bugs: #179354 ID: 200709-07:02 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Errata ===== The unaffected ebuild, as reported in the original version of this Security Advisory, did not properly address all vulnerabilities. All Eggdrop users should upgrade to net-irc/eggdrop-1.6.18-r3. The corrected sections appear below. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-irc/eggdrop < 1.6.18-r3 > = 1.6.18-r3 Resolution ========= All Eggdrop users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-irc/eggdrop-1.6.18-r3" Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200709-07 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to
It was discovered that eggdrop, an advanced IRC robot, was vulnerable to a buffer overflow which could result in a remote user executing arbitrary code.. - ------------------------------------------------------------------------Debian Security Advisory DSA-1448-1
It was discovered that eggdrop, an advanced IRC robot, was vulnerable to a buffer overflow which could result in a remote user executing arbitrary code.. - ------------------------------------------------------------------------Debian Security Advisory DSA-1448-1
Get the latest Linux and open source security news straight to your inbox.