ircu 2.10.12.05 and earlier ignores timestamps in bounces, which allows remote attackers to take over a channel during a netjoin by causing a bounce while a server with an older version of the channel is linking.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ircu | Universal_ircd | * | 2.10.12.05 (including) |
Ircd-ircu | Ubuntu | dapper | * |
Ircd-ircu | Ubuntu | edgy | * |
Ircd-ircu | Ubuntu | feisty | * |
Ircd-ircu | Ubuntu | gutsy | * |
Ircd-ircu | Ubuntu | upstream | * |