LWN.net Logo

unrealircd: multiple vulnerabilities

Package(s):unrealircd CVE #(s):
Created:June 15, 2010 Updated:June 16, 2010
Description: From the Gentoo advisory:

Multiple vulnerabilities have been reported in UnrealIRCd:

* The vendor reported a buffer overflow in the user authorization code.

* The vendor reported that the distributed source code of UnrealIRCd was compromised and altered to include a system() call that could be called with arbitrary user input.

A remote attacker could exploit these vulnerabilities to cause the execution of arbitrary commands with the privileges of the user running UnrealIRCd, or a Denial of Service condition.

Alerts:
Gentoo 201006-21 2010-06-14

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds