FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2007-6122

This CVE name corresponds to:

Entered Topic
2008-01-19 IRC Services-- Denial of Service Vulnerability

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2007-6122
Phase Assigned(20071126)

Description

The default_encrypt function in encrypt.c in IRC Services before 5.0.63, and 5.1.x before 5.1.7, allows remote attackers to cause a denial of service (daemon crash) via a long password. NOTE: some of these details are obtained from third party information.

References

Source Reference
MLIST [IRCServices] 20071121 Services 5.0.63 released
MLIST [IRCServices] 20071121 Services 5.1.7 released
CONFIRM http://www.ircservices.za.net/Changes.txt
CONFIRM http://bugs.gentoo.org/show_bug.cgi?id=199897
GENTOO GLSA-200712-12
BID 26517
VUPEN ADV-2007-3959
SECUNIA 27761
SECUNIA 28090
XF ircservices-password-dos(38591)