ircu 2.10.12.05 and earlier allows remote attackers to discover the hidden IP address of arbitrary +x users via a series of /silence commands with (1) CIDR mask arguments or (2) certain other arguments that represent groups of IP addresses, then monitoring CTCP ping replies.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ircu | Universal_ircd | * | 2.10.12.05 (including) |
Ircd-ircu | Ubuntu | dapper | * |
Ircd-ircu | Ubuntu | edgy | * |
Ircd-ircu | Ubuntu | feisty | * |
Ircd-ircu | Ubuntu | gutsy | * |
Ircd-ircu | Ubuntu | upstream | * |