[rt.blitzed.org #2957] cgiirc vulnerability

"Justin Pryzby via RT" <[email protected]> Wed, 10 May 2006 17:00:07 +0000 (UTC)
Newsgroups gmane.network.irc.blitzed.web
Message-ID <[email protected]>
Wed May 10 17:00:06 2006: Request 2957 was acted upon.
Transaction: Ticket created by [email protected]
       Queue: web
     Subject: cgiirc vulnerability
       Owner: Nobody
  Requestors: [email protected]
      Status: new
 Ticket <URL: http://rt.blitzed.org/Ticket/Display.html?id=2957 >


Please be advised that a new version of CGI IRC has been released
which fixes a buffer overflow:

  http://cgiirc.sourceforge.net/

Your site is running an older version which is likely affected by this
vulerability.

You should consider upgrading immediately (or installing a patched
copy of the older version, or disabling the service until it can be
fixed).  You should also know that a local vulnerability easily allows
a denial of service attack, and may allow further privilege
escalation, too.

You can read more about the vulnerability here:

  http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2148

Feel free to contact me for more info (I have been offering to assist
people in installing, upgrading, or patching their installations).

Justin