6.8
CVSSv2

CVE-2007-2807

Published: 22/05/2007 Updated: 10/07/2009
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Stack-based buffer overflow in mod/server.mod/servrmsg.c in Eggdrop 1.6.18, and possibly earlier, allows user-assisted, remote IRC servers to execute arbitrary code via a long private message.

Vulnerable Product Search on Vulmon Subscribe to Product

eggheads eggdrop irc bot 1.6.15

eggheads eggdrop irc bot 1.6.16

eggheads eggdrop irc bot 1.6.10

eggheads eggdrop irc bot 1.6.17

eggheads eggdrop irc bot 1.6.8

eggheads eggdrop irc bot 1.6.13

eggheads eggdrop irc bot 1.6.14

eggheads eggdrop irc bot 1.6.11

eggheads eggdrop irc bot 1.6.12

eggheads eggdrop irc bot 1.6.9

eggheads eggdrop irc bot

Vendor Advisories

Debian Bug report logs - #427157 CVE-2007-2807: stack-based buffer overflow Package: eggdrop; Maintainer for eggdrop is Cédric Barboiron <ced@winkiefr>; Source for eggdrop is src:eggdrop (PTS, buildd, popcon) Reported by: Florian Weimer <fw@denebenyode> Date: Sat, 2 Jun 2007 07:51:01 UTC Severity: grave Tags: s ...
Debian Bug report logs - #528778 eggdrop: incomplete patch for CVE-2007-2807 Package: eggdrop; Maintainer for eggdrop is Cédric Barboiron <ced@winkiefr>; Source for eggdrop is src:eggdrop (PTS, buildd, popcon) Reported by: Nico Golde <nion@debianorg> Date: Fri, 15 May 2009 12:21:04 UTC Severity: grave Tags: secur ...
Several vulnerabilities have been discovered in eggdrop, an advanced IRC robot The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2007-2807 It was discovered that eggdrop is vulnerable to a buffer overflow, which could result in a remote user executing arbitrary code The previous DSA (DSA-1448-1) did not fix ...
It was discovered that eggdrop, an advanced IRC robot, was vulnerable to a buffer overflow which could result in a remote user executing arbitrary code For the old stable distribution (sarge), this problem has been fixed in version 1617-3sarge1 For the stable distribution (etch), this problem has been fixed in version 1618-1etch1 For the uns ...

Exploits

/* Eggdrop Server Module Message Handling Remote Buffer Overflow Vulnerability wwwsecurityfocuscom/bid/24070 discovered by Bow Sineath tested on eggdrop 1618 / linux 24 -exploit is a fake ircd replace shellcode strip 0x00,0x0a and a few more probably remember to add \n at end of shellcode poison some dns cache or ...
Remote denial of service exploit for Eggdrop and Windrop version 1619 ...