The (1) Conn_StartLogin and (2) cb_Read_Resolver_Result functions in conn.c in ngIRCd 18 through 20.2, when the configuration option NoticeAuth is enabled, does not properly handle the return code for the Handle_Write function, which allows remote attackers to cause a denial of service (assertion failure and server crash) via unspecified vectors, related to a "notice auth" message not being sent to a new client.
2013-10-01T19:55:09.507
2025-04-11T00:51:21.963
Deferred
CVSSv2: 4.3 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:N/A:P
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | barton | ngircd | 18.0 | Yes |
Application | barton | ngircd | 19.0 | Yes |
Application | barton | ngircd | 19.1 | Yes |
Application | barton | ngircd | 20.0 | Yes |
Application | barton | ngircd | 20.1 | Yes |
Application | barton | ngircd | 20.2 | Yes |