7.8
CVSSv2

CVE-2007-4404

Published: 18/08/2007 Updated: 15/10/2018
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

ircu 2.10.12.01 allows remote malicious users to (1) cause a denial of service (flood wallops) by joining two channels with certain long names that differ in the final character, which triggers a protocol violation and (2) cause a denial of service (daemon crash) via a "J 0:#channel" message on a channel without an apass; and (3) allows remote authenticated operators to cause a denial of service (daemon crash) via a remote "names -D" command.

Vulnerable Product Search on Vulmon Subscribe to Product

universal ircd ircu 2.10.12.01

Vendor Advisories

Debian Bug report logs - #439314 Several security issues in ircu [CVE-2007-440411] Package: ircd-ircu; Maintainer for ircd-ircu is Martin Gerhard Loschwitz <madkiss@debianorg>; Source for ircd-ircu is src:ircd-ircu (PTS, buildd, popcon) Reported by: Thijs Kinkhorst <thijs@debianorg> Date: Fri, 24 Aug 2007 07:36:0 ...