CVE Vulnerabilities

CVE-2009-1789

Published: May 26, 2009 | Modified: Sep 29, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
LOW

mod/server.mod/servmsg.c in Eggheads Eggdrop and Windrop 1.6.19 and earlier allows remote attackers to cause a denial of service (crash) via a crafted PRIVMSG that causes an empty string to trigger a negative string length copy. NOTE: this issue exists because of an incorrect fix for CVE-2007-2807.

Affected Software

Name Vendor Start Version End Version
Eggdrop Eggheads 1.6.0 (including) 1.6.0 (including)
Eggdrop Eggheads 1.6.1 (including) 1.6.1 (including)
Eggdrop Eggheads 1.6.2 (including) 1.6.2 (including)
Eggdrop Eggheads 1.6.3 (including) 1.6.3 (including)
Eggdrop Eggheads 1.6.4 (including) 1.6.4 (including)
Eggdrop Eggheads 1.6.5 (including) 1.6.5 (including)
Eggdrop Eggheads 1.6.6 (including) 1.6.6 (including)
Eggdrop Eggheads 1.6.7 (including) 1.6.7 (including)
Eggdrop Eggheads 1.6.8 (including) 1.6.8 (including)
Eggdrop Eggheads 1.6.9 (including) 1.6.9 (including)
Eggdrop Eggheads 1.6.10 (including) 1.6.10 (including)
Eggdrop Eggheads 1.6.11 (including) 1.6.11 (including)
Eggdrop Eggheads 1.6.12 (including) 1.6.12 (including)
Eggdrop Eggheads 1.6.13 (including) 1.6.13 (including)
Eggdrop Eggheads 1.6.14 (including) 1.6.14 (including)
Eggdrop Eggheads 1.6.15 (including) 1.6.15 (including)
Eggdrop Eggheads 1.6.16 (including) 1.6.16 (including)
Eggdrop Eggheads 1.6.17 (including) 1.6.17 (including)
Eggdrop Eggheads 1.6.18 (including) 1.6.18 (including)
Eggdrop Eggheads 1.6.18-rc1 (including) 1.6.18-rc1 (including)
Eggdrop_irc_bot Eggheads * 1.6.19 (including)
Windrop Philip_moore * 1.6.19 (including)
Windrop Philip_moore 1.4.4 (including) 1.4.4 (including)
Windrop Philip_moore 1.4.6 (including) 1.4.6 (including)
Windrop Philip_moore 1.5.4 (including) 1.5.4 (including)
Windrop Philip_moore 1.5.4-rc1 (including) 1.5.4-rc1 (including)
Windrop Philip_moore 1.5.4-rc2 (including) 1.5.4-rc2 (including)
Windrop Philip_moore 1.5.4a (including) 1.5.4a (including)
Windrop Philip_moore 1.6.0 (including) 1.6.0 (including)
Windrop Philip_moore 1.6.0-rc1 (including) 1.6.0-rc1 (including)
Windrop Philip_moore 1.6.0-rc1-rel2 (including) 1.6.0-rc1-rel2 (including)
Windrop Philip_moore 1.6.1 (including) 1.6.1 (including)
Windrop Philip_moore 1.6.2+bindsfix (including) 1.6.2+bindsfix (including)
Windrop Philip_moore 1.6.3 (including) 1.6.3 (including)
Windrop Philip_moore 1.6.4-sr1 (including) 1.6.4-sr1 (including)
Windrop Philip_moore 1.6.6 (including) 1.6.6 (including)
Windrop Philip_moore 1.6.7 (including) 1.6.7 (including)
Windrop Philip_moore 1.6.8 (including) 1.6.8 (including)
Windrop Philip_moore 1.6.9 (including) 1.6.9 (including)
Windrop Philip_moore 1.6.10 (including) 1.6.10 (including)
Windrop Philip_moore 1.6.12 (including) 1.6.12 (including)
Windrop Philip_moore 1.6.13 (including) 1.6.13 (including)
Windrop Philip_moore 1.6.15 (including) 1.6.15 (including)
Windrop Philip_moore 1.6.16 (including) 1.6.16 (including)
Windrop Philip_moore 1.6.17 (including) 1.6.17 (including)
Windrop Philip_moore 1.6.18 (including) 1.6.18 (including)
Windrop Philip_moore 1.6.19+ctcpfix (including) 1.6.19+ctcpfix (including)
Eggdrop Ubuntu dapper *
Eggdrop Ubuntu devel *
Eggdrop Ubuntu hardy *
Eggdrop Ubuntu intrepid *
Eggdrop Ubuntu jaunty *
Eggdrop Ubuntu karmic *
Eggdrop Ubuntu lucid *
Eggdrop Ubuntu upstream *

References