Total vulnerabilities in the database
The (1) Conn_StartLogin and (2) cb_Read_Resolver_Result functions in conn.c in ngIRCd 18 through 20.2, when the configuration option NoticeAuth is enabled, does not properly handle the return code for the Handle_Write function, which allows remote attackers to cause a denial of service (assertion failure and server crash) via unspecified vectors, related to a "notice auth" message not being sent to a new client.
Software | From | Fixed in |
---|---|---|
barton / ngircd | 19.0 | 19.0.x |
barton / ngircd | 20.1 | 20.1.x |
barton / ngircd | 20.0 | 20.0.x |
barton / ngircd | 20.2 | 20.2.x |
barton / ngircd | 18.0 | 18.0.x |
barton / ngircd | 19.1 | 19.1.x |