Summary
The remote host is missing an update to eggdrop
announced via advisory DSA 1826-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%201826-1
Insight
Several vulnerabilities have been discovered in eggdrop, an advanced IRC robot. The Common Vulnerabilities and Exposures project identifies the following problems:
CVE-2007-2807
It was discovered that eggdrop is vulnerable to a buffer overflow, which could result in a remote user executing arbitrary code. The previous DSA (DSA-1448-1) did not fix the issue correctly.
CVE-2009-1789
It was discovered that eggdrop is vulnerable to a denial of service attack, that allows remote attackers to cause a crash via a crafted PRIVMSG.
For the stable distribution (lenny), these problems have been fixed in version 1.6.19-1.1+lenny1.
For the old stable distribution (etch), these problems have been fixed in version 1.6.18-1etch2.
For the unstable distribution (sid), this problem has been fixed in version 1.6.19-1.2
We recommend that you upgrade your eggdrop package.
Severity
Classification
-
CVE CVE-2007-2807, CVE-2009-1789 -
CVSS Base Score: 6.8
AV:N/AC:M/Au:N/C:P/I:P/A:P
Related Vulnerabilities