CVE-2007-6062: Input Validation
Published Nov 20, 2007
·Updated
irc-channel.c in ngIRCd before 0.10.3 allows remote attackers to cause a denial of service (crash) via a JOIN command without a channel argument.
Affected Software
1 affected component
ngircd ngircd<=0.10.3
Event History
Nov 20, 2007
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-6062?
CVE-2007-6062 has a severity rating of medium as it allows remote attackers to trigger a denial of service by exploiting a flaw in the JOIN command.
2
How do I fix CVE-2007-6062?
To fix CVE-2007-6062, upgrade ngIRCd to version 0.10.3 or later.
3
What type of attack does CVE-2007-6062 facilitate?
CVE-2007-6062 facilitates a denial of service attack by causing ngIRCd to crash when a JOIN command is issued without a channel argument.
4
Which versions of ngIRCd are affected by CVE-2007-6062?
CVE-2007-6062 affects all versions of ngIRCd prior to 0.10.3.
5
Can CVE-2007-6062 be exploited remotely?
Yes, CVE-2007-6062 can be exploited remotely by sending a malicious JOIN command without a channel argument.