Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 132749 - net-irc/emech DoS through empty CTCP in NOTICE
Summary: net-irc/emech DoS through empty CTCP in NOTICE
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL: http://www.energymech.net/
Whiteboard: B3? [glsa] jaervosz
Keywords:
Depends on:
Blocks:
 
Reported: 2006-05-08 19:32 UTC by Jérôme Poulin
Modified: 2006-06-26 12:27 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
Bump with segfault fixed and uptime + dns USE flags. (emech-3.0.2.ebuild,1.64 KB, text/plain)
2006-05-08 19:36 UTC, Jérôme Poulin
no flags Details

Note You need to log in before you can comment on or make changes to this bug.
Description Jérôme Poulin 2006-05-08 19:32:46 UTC
There was a security update which was just fixed about the bot segfaulting when it receives an empty CTCP in NOTICE and it would be important to update the ebuild ASAP, I also added 2 USE flags for 'uptime' reports and raw 'dns' resolving support which should not be activated all the time.
Comment 1 Jérôme Poulin 2006-05-08 19:36:15 UTC
Created attachment 86455 [details]
Bump with segfault fixed and uptime + dns USE flags.
Comment 2 Jakub Moc (RETIRED) gentoo-dev 2006-05-09 00:00:19 UTC
Does security want this? Looks like a good way to DoS the thing to me... ;)
Comment 3 Jérôme Poulin 2006-06-05 19:47:20 UTC
Let's move on! It's been here for a while and did not even make its way to portage yet. (Did I misset severity to minor?)
Comment 4 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2006-06-11 14:04:41 UTC
Hi IRC team, emech seems to have a security issue, please bump an updated ebuild.

Jakub: thanks
J
Comment 5 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2006-06-11 14:04:41 UTC
Hi IRC team, emech seems to have a security issue, please bump an updated ebuild.

Jakub: thanks
Jérome: désolé pour le lag :/ . La sévérité est effectivement "minor" :)


From http://www.energymech.net/ :
"EnergyMech 3.0.2
Contains a critical bugfix. Yes we're still alive. Download it now "

Comment 6 Alec Warner (RETIRED) archtester gentoo-dev Security 2006-06-11 17:51:05 UTC
revbumped, security, you need anything else?
Comment 7 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2006-06-12 02:48:48 UTC
Thanks Antarus.
(Whereas i'm not sure that the 2.x branch is affected.)

x86 & ppc, please mark 3.0.2 stable, thanks in advance

Comment 8 Jérôme Poulin 2006-06-13 16:35:55 UTC
Just seen the new ebuild version pop-up in portage but still does not contains the 'uptime' and 'dns' use flags to allow disabling uptime reports and raw dns resolving, not everyone wants that and I would consider important adding those too. The eBuild I attached is a modified version which only adds those two flags. Thanks.
Comment 9 Tobias Scherbaum (RETIRED) gentoo-dev 2006-06-14 11:21:48 UTC
ppc stable
Comment 10 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-06-16 11:19:48 UTC
Seems misplaced in auditing and fixing status whiteboard.

x86 please test and mark stable if possible.
Comment 11 Joshua Jackson (RETIRED) gentoo-dev 2006-06-21 19:32:48 UTC
x86 done
Comment 12 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-06-22 05:42:54 UTC
Time for GLSA vote. I tend to vote NO.
Comment 13 Wolf Giesen (RETIRED) gentoo-dev 2006-06-22 05:45:14 UTC
Can't be sure without the source, but from "empty CTCP" I'd vote another "no".
Comment 14 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2006-06-22 05:51:46 UTC
i vote yes :

1. to send an empty CTCP is trivial;

2. it's very worrying for the user (it's not like a Xine DoS: on IRC, you could be banned or akilled if you're rejoining too often. And it pollutes the logs);

3. and many IRC users love to play such stupid games.
Comment 15 Thierry Carrez (RETIRED) gentoo-dev 2006-06-22 10:19:42 UTC
I vote YES. DoS on IRC is evil :)
Comment 16 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-06-22 11:16:01 UTC
Ok, lets have a GLSA.
Comment 17 Thierry Carrez (RETIRED) gentoo-dev 2006-06-26 12:27:13 UTC
Sent as GLSA 200606-26