The Server-Server protocol implementation in ngIRCd before 26~rc2 allows an out-of-bounds access, as demonstrated by the IRC_NJOIN() function. (CVE-2020-14148) References: . MGASA-2020-0340 - Updated ngircd package fixes security vulnerability Publication date: 20 Aug 2020 URL: https://advisories.mageia.org/MGASA-2020-0340.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-14148 The Server-Server protocol implementation in ngIRCd before 26~rc2 allows an out-of-bounds access, as demonstrated by the IRC_NJOIN() function. (CVE-2020-14148) References: - https://bugs.mageia.org/show_bug.cgi?id=26853 - https://lists.debian.org/debian-lts-announce/2020/06/msg00023.html - https://www.cve.org/CVERecord?id=CVE-2020-14148 SRPMS: - 7/core/ngircd-25-1.1.mga7 . Mageia 2021-0420 upgrades ngircd to address potential buffer overflow issue. Comprehensive information regarding the patch is provided.. ngircd Security Update, Mageia 2020-0340, Out-Of-Bounds Access, Server Protocol Vulnerability, Security Advisory. . LinuxSecurity.com Team
It was discovered that there was an out-of-bounds access vulnerability in the server-server protocol in the ngircd Internet Relay Chat (IRC) server. . Package : ngircd Version : 22-2+deb8u1 CVE ID : CVE-2020-14148 Debian Bug : #963147 It was discovered that there was an out-of-bounds access vulnerability in the server-server protocol in the ngircd Internet Relay Chat (IRC) server. For Debian 8 "Jessie", this issue has been fixed in ngircd version 22-2+deb8u1. We recommend that you upgrade your ngircd packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS Regards, - -- ,'`. : :' : Chris Lamb `. `'`
Get the latest Linux and open source security news straight to your inbox.