CVE-2009-1789
26.05.2009, 16:30
mod/server.mod/servmsg.c in Eggheads Eggdrop and Windrop 1.6.19 and earlier allows remote attackers to cause a denial of service (crash) via a crafted PRIVMSG that causes an empty string to trigger a negative string length copy. NOTE: this issue exists because of an incorrect fix for CVE-2007-2807.Enginsight
| Vendor | Product | Version |
|---|---|---|
| eggheads | eggdrop | 1.6.0 |
| eggheads | eggdrop | 1.6.1 |
| eggheads | eggdrop | 1.6.2 |
| eggheads | eggdrop | 1.6.3 |
| eggheads | eggdrop | 1.6.4 |
| eggheads | eggdrop | 1.6.5 |
| eggheads | eggdrop | 1.6.6 |
| eggheads | eggdrop | 1.6.7 |
| eggheads | eggdrop | 1.6.8 |
| eggheads | eggdrop | 1.6.9 |
| eggheads | eggdrop | 1.6.10 |
| eggheads | eggdrop | 1.6.11 |
| eggheads | eggdrop | 1.6.12 |
| eggheads | eggdrop | 1.6.13 |
| eggheads | eggdrop | 1.6.14 |
| eggheads | eggdrop | 1.6.15 |
| eggheads | eggdrop | 1.6.16 |
| eggheads | eggdrop | 1.6.17 |
| eggheads | eggdrop | 1.6.18 |
| eggheads | eggdrop | 1.6.18:rc1 |
| eggheads | eggdrop_irc_bot | 𝑥 ≤ 1.6.19 |
| philip_moore | windrop | 𝑥 ≤ 1.6.19 |
| philip_moore | windrop | 1.4.4 |
| philip_moore | windrop | 1.4.6 |
| philip_moore | windrop | 1.5.4 |
| philip_moore | windrop | 1.5.4:rc1 |
| philip_moore | windrop | 1.5.4:rc2 |
| philip_moore | windrop | 1.5.4a:a |
| philip_moore | windrop | 1.6.0 |
| philip_moore | windrop | 1.6.0:rc1 |
| philip_moore | windrop | 1.6.0:rc1-rel2 |
| philip_moore | windrop | 1.6.1 |
| philip_moore | windrop | 1.6.2\+bindsfix |
| philip_moore | windrop | 1.6.3 |
| philip_moore | windrop | 1.6.4:sr1 |
| philip_moore | windrop | 1.6.6 |
| philip_moore | windrop | 1.6.7 |
| philip_moore | windrop | 1.6.8 |
| philip_moore | windrop | 1.6.9 |
| philip_moore | windrop | 1.6.10 |
| philip_moore | windrop | 1.6.12 |
| philip_moore | windrop | 1.6.13 |
| philip_moore | windrop | 1.6.15 |
| philip_moore | windrop | 1.6.16 |
| philip_moore | windrop | 1.6.17 |
| philip_moore | windrop | 1.6.18 |
| philip_moore | windrop | 1.6.19\+ctcpfix |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
References