CVE-2013-5580

NameCVE-2013-5580
DescriptionThe (1) Conn_StartLogin and (2) cb_Read_Resolver_Result functions in conn.c in ngIRCd 18 through 20.2, when the configuration option NoticeAuth is enabled, does not properly handle the return code for the Handle_Write function, which allows remote attackers to cause a denial of service (assertion failure and server crash) via unspecified vectors, related to a "notice auth" message not being sent to a new client.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
ngircd (PTS)jessie, jessie (lts)22-2+deb8u1fixed
stretch24-1fixed
buster25-2fixed
bullseye26.1-1+deb11u1fixed
bookworm26.1-1+deb12u1fixed
sid, trixie27-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
ngircdsource(unstable)(not affected)

Notes

- ngircd <not-affected> (only affects 20, 20.1, and 20.2)
http://arthur.barton.de/pipermail/ngircd-ml/2013-August/000652.html

Search for package or bug name: Reporting problems