Non-registered IRC users using (1) ircd-hybrid 7.0.1 and earlier, (2) ircd-ratbox 1.5.1 and earlier, or (3) ircd-ratbox 2.0rc6 and earlier do not have a rate-limit imposed, which could allow remote attackers to cause a denial of service by repeatedly making requests, which are slowly dequeued.
Software | From | Fixed in |
---|---|---|
ircd-ratbox / ircd-ratbox | - | 1.5.1.x |
ircd-hybrid / ircd-hybrid | - | 7.0.1.x |
ircd-ratbox / ircd-ratbox | - | 2.0_rc6.x |