4.3

CVE-2009-1789

mod/server.mod/servmsg.c in Eggheads Eggdrop and Windrop 1.6.19 and earlier allows remote attackers to cause a denial of service (crash) via a crafted PRIVMSG that causes an empty string to trigger a negative string length copy.  NOTE: this issue exists because of an incorrect fix for CVE-2007-2807.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
EggheadsEggdrop Version1.6.0
EggheadsEggdrop Version1.6.1
EggheadsEggdrop Version1.6.2
EggheadsEggdrop Version1.6.3
EggheadsEggdrop Version1.6.4
EggheadsEggdrop Version1.6.5
EggheadsEggdrop Version1.6.6
EggheadsEggdrop Version1.6.7
EggheadsEggdrop Version1.6.8
EggheadsEggdrop Version1.6.9
EggheadsEggdrop Version1.6.10
EggheadsEggdrop Version1.6.11
EggheadsEggdrop Version1.6.12
EggheadsEggdrop Version1.6.13
EggheadsEggdrop Version1.6.14
EggheadsEggdrop Version1.6.15
EggheadsEggdrop Version1.6.16
EggheadsEggdrop Version1.6.17
EggheadsEggdrop Version1.6.18
EggheadsEggdrop Version1.6.18 Updaterc1
EggheadsEggdrop Irc Bot Version <= 1.6.19
Philip MooreWindrop Version <= 1.6.19
Philip MooreWindrop Version1.4.4 Editionfinal
Philip MooreWindrop Version1.4.6
Philip MooreWindrop Version1.5.4 Editionfinal
Philip MooreWindrop Version1.5.4 Updaterc1
Philip MooreWindrop Version1.5.4 Updaterc2
Philip MooreWindrop Version1.5.4a
Philip MooreWindrop Version1.6.0 Editionfinal
Philip MooreWindrop Version1.6.0 Updaterc1
Philip MooreWindrop Version1.6.0 Updaterc1-rel2
Philip MooreWindrop Version1.6.1
Philip MooreWindrop Version1.6.3
Philip MooreWindrop Version1.6.4 Updatesr1
Philip MooreWindrop Version1.6.6
Philip MooreWindrop Version1.6.7
Philip MooreWindrop Version1.6.8
Philip MooreWindrop Version1.6.9
Philip MooreWindrop Version1.6.10
Philip MooreWindrop Version1.6.12
Philip MooreWindrop Version1.6.13
Philip MooreWindrop Version1.6.15
Philip MooreWindrop Version1.6.16
Philip MooreWindrop Version1.6.17
Philip MooreWindrop Version1.6.18
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 8.49% 0.943
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:N/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/35690
http://www.debian.org/security/2009/dsa-1826
http://archives.neohapsis.com/archives/fulldisclosure/2009-05/0129.html
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=528778
http://cvs.eggheads.org/viewvc/viewvc.cgi/eggdrop1.6/doc/Changes1.6?revision=1.20&view=markup
Patch
Vendor Advisory
http://osvdb.org/54460
http://secunia.com/advisories/35104
Vendor Advisory
http://secunia.com/advisories/35158
http://www.mandriva.com/security/advisories?name=MDVSA-2009:126
http://www.securityfocus.com/archive/1/503574
http://www.securityfocus.com/bid/34985
http://www.vupen.com/english/advisories/2009/1340
Patch
Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/50547
https://www.exploit-db.com/exploits/8695
https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01333.html
https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01337.html