CVE-2013-5580: Input Validation
The (1) ConnStartLogin and (2) cbReadResolverResult functions in conn.c in ngIRCd 18 through 20.2, when the configuration option NoticeAuth is enabled, does not properly handle the return code for the HandleWrite function, which allows remote attackers to cause a denial of service (assertion failure and server crash) via unspecified vectors, related to a "notice auth" message not being sent to a new client.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2013-5580?
CVE-2013-5580 has a severity rating that indicates it can lead to a denial of service condition.
How do I fix CVE-2013-5580?
To fix CVE-2013-5580, users should upgrade ngIRCd to version 20.3 or later where the vulnerability is addressed.
Which versions of ngIRCd are affected by CVE-2013-5580?
Versions of ngIRCd from 18.0 up to 20.2 are affected by CVE-2013-5580.
What kind of attack does CVE-2013-5580 enable?
CVE-2013-5580 enables remote attackers to execute a denial-of-service attack.
Is CVE-2013-5580 related to configuration options in ngIRCd?
Yes, CVE-2013-5580 is associated with the NoticeAuth configuration option in ngIRCd.