CVE Vulnerabilities

CVE-2009-1789

Published: May 26, 2009 | Modified: Sep 29, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

mod/server.mod/servmsg.c in Eggheads Eggdrop and Windrop 1.6.19 and earlier allows remote attackers to cause a denial of service (crash) via a crafted PRIVMSG that causes an empty string to trigger a negative string length copy. NOTE: this issue exists because of an incorrect fix for CVE-2007-2807.

Affected Software

Name Vendor Start Version End Version
Eggdrop Eggheads 1.6.0 (including) 1.6.0 (including)
Eggdrop Eggheads 1.6.1 (including) 1.6.1 (including)
Eggdrop Eggheads 1.6.2 (including) 1.6.2 (including)
Eggdrop Eggheads 1.6.3 (including) 1.6.3 (including)
Eggdrop Eggheads 1.6.4 (including) 1.6.4 (including)
Eggdrop Eggheads 1.6.5 (including) 1.6.5 (including)
Eggdrop Eggheads 1.6.6 (including) 1.6.6 (including)
Eggdrop Eggheads 1.6.7 (including) 1.6.7 (including)
Eggdrop Eggheads 1.6.8 (including) 1.6.8 (including)
Eggdrop Eggheads 1.6.9 (including) 1.6.9 (including)
Eggdrop Eggheads 1.6.10 (including) 1.6.10 (including)
Eggdrop Eggheads 1.6.11 (including) 1.6.11 (including)
Eggdrop Eggheads 1.6.12 (including) 1.6.12 (including)
Eggdrop Eggheads 1.6.13 (including) 1.6.13 (including)
Eggdrop Eggheads 1.6.14 (including) 1.6.14 (including)
Eggdrop Eggheads 1.6.15 (including) 1.6.15 (including)
Eggdrop Eggheads 1.6.16 (including) 1.6.16 (including)
Eggdrop Eggheads 1.6.17 (including) 1.6.17 (including)
Eggdrop Eggheads 1.6.18 (including) 1.6.18 (including)
Eggdrop Eggheads 1.6.18-rc1 (including) 1.6.18-rc1 (including)
Eggdrop_irc_bot Eggheads * 1.6.19 (including)
Windrop Philip_moore * 1.6.19 (including)
Windrop Philip_moore 1.4.4 (including) 1.4.4 (including)
Windrop Philip_moore 1.4.6 (including) 1.4.6 (including)
Windrop Philip_moore 1.5.4 (including) 1.5.4 (including)
Windrop Philip_moore 1.5.4-rc1 (including) 1.5.4-rc1 (including)
Windrop Philip_moore 1.5.4-rc2 (including) 1.5.4-rc2 (including)
Windrop Philip_moore 1.5.4a (including) 1.5.4a (including)
Windrop Philip_moore 1.6.0 (including) 1.6.0 (including)
Windrop Philip_moore 1.6.0-rc1 (including) 1.6.0-rc1 (including)
Windrop Philip_moore 1.6.0-rc1-rel2 (including) 1.6.0-rc1-rel2 (including)
Windrop Philip_moore 1.6.1 (including) 1.6.1 (including)
Windrop Philip_moore 1.6.2+bindsfix (including) 1.6.2+bindsfix (including)
Windrop Philip_moore 1.6.3 (including) 1.6.3 (including)
Windrop Philip_moore 1.6.4-sr1 (including) 1.6.4-sr1 (including)
Windrop Philip_moore 1.6.6 (including) 1.6.6 (including)
Windrop Philip_moore 1.6.7 (including) 1.6.7 (including)
Windrop Philip_moore 1.6.8 (including) 1.6.8 (including)
Windrop Philip_moore 1.6.9 (including) 1.6.9 (including)
Windrop Philip_moore 1.6.10 (including) 1.6.10 (including)
Windrop Philip_moore 1.6.12 (including) 1.6.12 (including)
Windrop Philip_moore 1.6.13 (including) 1.6.13 (including)
Windrop Philip_moore 1.6.15 (including) 1.6.15 (including)
Windrop Philip_moore 1.6.16 (including) 1.6.16 (including)
Windrop Philip_moore 1.6.17 (including) 1.6.17 (including)
Windrop Philip_moore 1.6.18 (including) 1.6.18 (including)
Windrop Philip_moore 1.6.19+ctcpfix (including) 1.6.19+ctcpfix (including)

References