CVE-2013-1747: Medium severity ngircd vulnerability
Published Mar 28, 2013
·Updated
channel.c in ngIRCd 20 and 20.1 allows remote attackers to cause a denial of service (assertion failure and crash) via a KICK command for a user who is not on the associated channel.
Affected Software
2 affected components
ngircd ngircd=20
ngircd ngircd=20.1
Event History
Mar 28, 2013
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-1747?
CVE-2013-1747 is classified as a denial of service vulnerability.
2
How do I fix CVE-2013-1747?
To fix CVE-2013-1747, upgrade to ngIRCd version 20.2 or later.
3
What impact does CVE-2013-1747 have on ngIRCd users?
CVE-2013-1747 can cause ngIRCd to crash when a KICK command is issued for a user not on the channel.
4
Which versions of ngIRCd are affected by CVE-2013-1747?
ngIRCd versions 20 and 20.1 are affected by CVE-2013-1747.
5
Can CVE-2013-1747 be exploited remotely?
Yes, CVE-2013-1747 can be exploited remotely by sending a specific KICK command.