First published: Tue Jan 15 2008(Updated: )
ngIRCd 0.10.x before 0.10.4 and 0.11.0 before 0.11.0-pre2 allows remote attackers to cause a denial of service (crash) via crafted IRC PART message, which triggers an invalid dereference.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ngircd | <=0.11.0-pre1 | |
Ngircd | <=0.10.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-0285 has a severity rating of medium due to its denial of service impact.
To fix CVE-2008-0285, upgrade ngIRCd to version 0.10.4 or later, or 0.11.0-pre2 or later.
CVE-2008-0285 is caused by an invalid dereference triggered by a crafted IRC PART message.
CVE-2008-0285 affects ngIRCd versions 0.10.x prior to 0.10.4 and 0.11.0 prior to 0.11.0-pre2.
The best option is to upgrade to a fixed version, as no official workaround is provided for CVE-2008-0285.