Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 482582 (CVE-2013-5580) - <net-irc/ngircd-20.3: "Handle_Write" Denial of Service Vulnerabilities (CVE-2013-5580)
Summary: <net-irc/ngircd-20.3: "Handle_Write" Denial of Service Vulnerabilities (CVE-2...
Status: RESOLVED FIXED
Alias: CVE-2013-5580
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://secunia.com/advisories/54567/
Whiteboard: C3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2013-08-26 17:33 UTC by Agostino Sarubbo
Modified: 2013-10-06 14:31 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2013-08-26 17:33:24 UTC
From ${URL} :

Description

Two vulnerabilities have been reported in ngIRCd, which can be exploited by malicious people to 
cause a DoS (Denial of Service).

The vulnerabilities are caused due to the "Conn_StartLogin()" and "cb_Read_Resolver_Result()" 
functions (ngircd/conn.c) not properly checking the return value of the "Handle_Write()" function 
and can be exploited to cause crashes.

Successful exploitation of the vulnerabilities requires "NoticeAuth" configuration to be enabled 
(disabled by default).

The vulnerabilities are reported in versions prior to 20.3.


Solution:
Update to version 20.3.

Provided and/or discovered by:
Reported by the vendor.

Original Advisory:
http://arthur.barton.de/pipermail/ngircd-ml/2013-August/000645.html


@maintainer(s): after the bump, in case we need to stabilize the package, please say explicitly if it is ready for the stabilization or not.
Comment 1 Chris Reffett (RETIRED) gentoo-dev Security 2013-10-02 03:53:51 UTC
Maintainer timeout. Arches, please test and stabilize:
=net-irc/ngircd-20.3
Target arch: x86
Comment 2 GLSAMaker/CVETool Bot gentoo-dev 2013-10-02 03:54:29 UTC
CVE-2013-5580 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-5580):
  The (1) Conn_StartLogin and (2) cb_Read_Resolver_Result functions in conn.c
  in ngIRCd 18 through 20.2, when the configuration option NoticeAuth is
  enabled, does not properly handle the return code for the Handle_Write
  function, which allows remote attackers to cause a denial of service
  (assertion failure and server crash) via unspecified vectors, related to a
  "notice auth" message not being sent to a new client.
Comment 3 Agostino Sarubbo gentoo-dev 2013-10-06 07:51:10 UTC
x86 stable
Comment 4 Sean Amoss (RETIRED) gentoo-dev Security 2013-10-06 14:19:21 UTC
GLSA vote: no.
Comment 5 Chris Reffett (RETIRED) gentoo-dev Security 2013-10-06 14:31:06 UTC
GLSA vote: no, closing noglsa.