Summary
The remote host is missing updates announced in
advisory GLSA 200312-06.
Solution
For Gentoo users, xchat-2.0.6 was marked ~arch (unstable) for most architectures. Since it was never marked as stable in the portage tree, only xchat users who have explictly added the unstable keyword to ACCEPT_KEYWORDS are affected. Users may updated affected machines to the patched version of xchat using the following commands:
# emerge sync
# emerge -pv '>=net-irc/xchat-2.0.6-r1'
# emerge '>=net-irc/xchat-2.0.6-r1'
# emerge clean
This assumes that users are running with ACCEPT_KEYWORDS enabled for their architecture.
http://www.securityspace.com/smysecure/catid.html?in=GLSA%20200312-06 http://bugs.gentoo.org/show_bug.cgi?id=35623
http://mail.nl.linux.org/xchat-announce/2003-12/msg00000.html
Insight
A bug in XChat could allow malformed dcc send requests to cause a denial of service.