5

CVE-2007-6122

The default_encrypt function in encrypt.c in IRC Services before 5.0.63, and 5.1.x before 5.1.7, allows remote attackers to cause a denial of service (daemon crash) via a long password.  NOTE: some of these details are obtained from third party information.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Irc ServicesIrc Services Version <= 5.0.62
Irc ServicesIrc Services Version <= 5.1.7
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.08% 0.791
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://www.ircservices.za.net/Changes.txt
http://bugs.gentoo.org/show_bug.cgi?id=199897
http://lists.ircservices.za.net/pipermail/ircservices/2007/005558.html
http://lists.ircservices.za.net/pipermail/ircservices/2007/005564.html
Patch
http://secunia.com/advisories/27761
Vendor Advisory
http://secunia.com/advisories/28090
http://security.gentoo.org/glsa/glsa-200712-12.xml
http://www.securityfocus.com/bid/26517
Patch
http://www.vupen.com/english/advisories/2007/3959
https://exchange.xforce.ibmcloud.com/vulnerabilities/38591