CVE-2009-4652: Low severity ngircd ngircd vulnerability
The (1) ConnGetCipherInfo and (2) ConnUsesSSL functions in src/ngircd/conn.c in ngIRCd 13 and 14, when SSL/TLS support is present and standalone mode is disabled, allow remote attackers to cause a denial of service (application crash) by sending the MOTD command from another server in the same IRC network, possibly related to an array index error.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-4652?
CVE-2009-4652 is classified as a denial of service vulnerability that can lead to application crashes.
How do I fix CVE-2009-4652?
To mitigate CVE-2009-4652, upgrade to a newer version of ngIRCd that addresses this vulnerability.
What versions of ngIRCd are affected by CVE-2009-4652?
CVE-2009-4652 affects ngIRCd versions 13 and 14.
What causes the vulnerability CVE-2009-4652?
CVE-2009-4652 is caused by improper handling of the MOTD command leading to application crashes.
Can CVE-2009-4652 be exploited remotely?
Yes, CVE-2009-4652 can be exploited by remote attackers within the same IRC network.