mod/server.mod/servmsg.c in Eggheads Eggdrop and Windrop 1.6.19 and earlier allows remote attackers to cause a denial of service (crash) via a crafted PRIVMSG that causes an empty string to trigger a negative string length copy. NOTE: this issue exists because of an incorrect fix for CVE-2007-2807.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Eggdrop | Eggheads | 1.6.0 (including) | 1.6.0 (including) |
Eggdrop | Eggheads | 1.6.1 (including) | 1.6.1 (including) |
Eggdrop | Eggheads | 1.6.2 (including) | 1.6.2 (including) |
Eggdrop | Eggheads | 1.6.3 (including) | 1.6.3 (including) |
Eggdrop | Eggheads | 1.6.4 (including) | 1.6.4 (including) |
Eggdrop | Eggheads | 1.6.5 (including) | 1.6.5 (including) |
Eggdrop | Eggheads | 1.6.6 (including) | 1.6.6 (including) |
Eggdrop | Eggheads | 1.6.7 (including) | 1.6.7 (including) |
Eggdrop | Eggheads | 1.6.8 (including) | 1.6.8 (including) |
Eggdrop | Eggheads | 1.6.9 (including) | 1.6.9 (including) |
Eggdrop | Eggheads | 1.6.10 (including) | 1.6.10 (including) |
Eggdrop | Eggheads | 1.6.11 (including) | 1.6.11 (including) |
Eggdrop | Eggheads | 1.6.12 (including) | 1.6.12 (including) |
Eggdrop | Eggheads | 1.6.13 (including) | 1.6.13 (including) |
Eggdrop | Eggheads | 1.6.14 (including) | 1.6.14 (including) |
Eggdrop | Eggheads | 1.6.15 (including) | 1.6.15 (including) |
Eggdrop | Eggheads | 1.6.16 (including) | 1.6.16 (including) |
Eggdrop | Eggheads | 1.6.17 (including) | 1.6.17 (including) |
Eggdrop | Eggheads | 1.6.18 (including) | 1.6.18 (including) |
Eggdrop | Eggheads | 1.6.18-rc1 (including) | 1.6.18-rc1 (including) |
Eggdrop_irc_bot | Eggheads | * | 1.6.19 (including) |
Windrop | Philip_moore | * | 1.6.19 (including) |
Windrop | Philip_moore | 1.4.4 (including) | 1.4.4 (including) |
Windrop | Philip_moore | 1.4.6 (including) | 1.4.6 (including) |
Windrop | Philip_moore | 1.5.4 (including) | 1.5.4 (including) |
Windrop | Philip_moore | 1.5.4-rc1 (including) | 1.5.4-rc1 (including) |
Windrop | Philip_moore | 1.5.4-rc2 (including) | 1.5.4-rc2 (including) |
Windrop | Philip_moore | 1.5.4a (including) | 1.5.4a (including) |
Windrop | Philip_moore | 1.6.0 (including) | 1.6.0 (including) |
Windrop | Philip_moore | 1.6.0-rc1 (including) | 1.6.0-rc1 (including) |
Windrop | Philip_moore | 1.6.0-rc1-rel2 (including) | 1.6.0-rc1-rel2 (including) |
Windrop | Philip_moore | 1.6.1 (including) | 1.6.1 (including) |
Windrop | Philip_moore | 1.6.2+bindsfix (including) | 1.6.2+bindsfix (including) |
Windrop | Philip_moore | 1.6.3 (including) | 1.6.3 (including) |
Windrop | Philip_moore | 1.6.4-sr1 (including) | 1.6.4-sr1 (including) |
Windrop | Philip_moore | 1.6.6 (including) | 1.6.6 (including) |
Windrop | Philip_moore | 1.6.7 (including) | 1.6.7 (including) |
Windrop | Philip_moore | 1.6.8 (including) | 1.6.8 (including) |
Windrop | Philip_moore | 1.6.9 (including) | 1.6.9 (including) |
Windrop | Philip_moore | 1.6.10 (including) | 1.6.10 (including) |
Windrop | Philip_moore | 1.6.12 (including) | 1.6.12 (including) |
Windrop | Philip_moore | 1.6.13 (including) | 1.6.13 (including) |
Windrop | Philip_moore | 1.6.15 (including) | 1.6.15 (including) |
Windrop | Philip_moore | 1.6.16 (including) | 1.6.16 (including) |
Windrop | Philip_moore | 1.6.17 (including) | 1.6.17 (including) |
Windrop | Philip_moore | 1.6.18 (including) | 1.6.18 (including) |
Windrop | Philip_moore | 1.6.19+ctcpfix (including) | 1.6.19+ctcpfix (including) |
Eggdrop | Ubuntu | dapper | * |
Eggdrop | Ubuntu | devel | * |
Eggdrop | Ubuntu | hardy | * |
Eggdrop | Ubuntu | intrepid | * |
Eggdrop | Ubuntu | jaunty | * |
Eggdrop | Ubuntu | karmic | * |
Eggdrop | Ubuntu | lucid | * |
Eggdrop | Ubuntu | upstream | * |