CVE-2008-0285: Medium severity ngircd vulnerability
Published Jan 15, 2008
·Updated
ngIRCd 0.10.x before 0.10.4 and 0.11.0 before 0.11.0-pre2 allows remote attackers to cause a denial of service (crash) via crafted IRC PART message, which triggers an invalid dereference.
Affected Software
2 affected components
ngircd ngircd<=0.11.0-pre1
ngircd ngircd<=0.10.3
Event History
Jan 15, 2008
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-0285?
CVE-2008-0285 has a severity rating of medium due to its denial of service impact.
2
How do I fix CVE-2008-0285?
To fix CVE-2008-0285, upgrade ngIRCd to version 0.10.4 or later, or 0.11.0-pre2 or later.
3
What causes CVE-2008-0285?
CVE-2008-0285 is caused by an invalid dereference triggered by a crafted IRC PART message.
4
Which versions are affected by CVE-2008-0285?
CVE-2008-0285 affects ngIRCd versions 0.10.x prior to 0.10.4 and 0.11.0 prior to 0.11.0-pre2.
5
Is there a workaround for CVE-2008-0285?
The best option is to upgrade to a fixed version, as no official workaround is provided for CVE-2008-0285.