LWN.net Logo

Mageia alert MGASA-2013-0265 (ngircd)

From:  Mageia Updates <buildsystem-daemon@mageia.org>
To:  updates-announce@ml.mageia.org
Subject:  [updates-announce] MGASA-2013-0265: Updated ngircd package fixes CVE-2013-5580
Date:  Fri, 30 Aug 2013 19:33:21 +0200
Message-ID:  <20130830173321.5B69F48782@valstar.mageia.org>
Archive-link:  Article, Thread

MGASA-2013-0265 - Updated ngircd package fixes CVE-2013-5580 Publication date: 30 Aug 2013 URL: http://advisories.mageia.org/MGASA-2013-0265.html Type: security Affected Mageia releases: 3 CVE: CVE-2013-5580 Description: Updated ngircd package fixes security vulnerability: Denial of service bug (server crash) in ngIRCd before 20.3 which could happen when the configuration option "NoticeAuth" is enabled (which is NOT the default) and ngIRCd failed to send the "notice auth" messages to new clients connecting to the server (CVE-2013-5580). References: - http://arthur.barton.de/pipermail/ngircd-ml/2013-August/0... - http://ngircd.barton.de/news.php.en - https://bugs.mageia.org/show_bug.cgi?id=11082 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5580 SRPMS: - 3/core/ngircd-20.3-1.mga3


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds