CVE-2010-3071: Null Pointer Dereference
A denial of service flaw was found in the way Bip IRC Bouncer exchanged user credentials by initiating the IRC protocol session. A remote, unauthenticated user could send a specially crafted connection request, leading to bip daemon crash (NULL pointer dereference)
References: [1] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=595409
Other sources
bip before 0.8.6 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an empty USER command.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3071?
CVE-2010-3071 has a severity rating that indicates it poses a denial of service risk.
How do I fix CVE-2010-3071?
To fix CVE-2010-3071, upgrade to a version of Bip IRC Bouncer that has patched the vulnerability.
Which versions of Bip are affected by CVE-2010-3071?
CVE-2010-3071 affects Bip versions from 0.7.0 through 0.8.5 inclusive.
Can CVE-2010-3071 be exploited remotely?
Yes, CVE-2010-3071 can be exploited by a remote, unauthenticated user.
What type of attack is associated with CVE-2010-3071?
CVE-2010-3071 is associated with a denial of service attack that may cause the bip daemon to crash.