First published: Thu Mar 28 2013(Updated: )
channel.c in ngIRCd 20 and 20.1 allows remote attackers to cause a denial of service (assertion failure and crash) via a KICK command for a user who is not on the associated channel.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ngircd Ngircd | =20 | |
Ngircd Ngircd | =20.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-1747 is classified as a denial of service vulnerability.
To fix CVE-2013-1747, upgrade to ngIRCd version 20.2 or later.
CVE-2013-1747 can cause ngIRCd to crash when a KICK command is issued for a user not on the channel.
ngIRCd versions 20 and 20.1 are affected by CVE-2013-1747.
Yes, CVE-2013-1747 can be exploited remotely by sending a specific KICK command.