CVE-2009-4652

NameCVE-2009-4652
DescriptionThe (1) Conn_GetCipherInfo and (2) Conn_UsesSSL functions in src/ngircd/conn.c in ngIRCd 13 and 14, when SSL/TLS support is present and standalone mode is disabled, allow remote attackers to cause a denial of service (application crash) by sending the MOTD command from another server in the same IRC network, possibly related to an array index error.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
ngircd (PTS)jessie, jessie (lts)22-2+deb8u1fixed
stretch24-1fixed
buster25-2fixed
bullseye26.1-1+deb11u1fixed
bookworm26.1-1+deb12u1fixed
sid, trixie27-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
ngircdsourcelenny(not affected)
ngircdsource(unstable)15-0.1

Notes

[lenny] - ngircd <not-affected> (SSL/TLS support not yet present)

Search for package or bug name: Reporting problems