oss-sec mailing list archives

Re: CVE request: UnrealIRCd 3.2.8.1 source code contained a backdoor allowing for remote command execution


From: "Steven M. Christey" <coley () linus mitre org>
Date: Mon, 14 Jun 2010 16:20:29 -0400 (EDT)


On Mon, 14 Jun 2010, Josh Bressers wrote:

Can you give this one a 2009 ID.

Use CVE-2009-4893

- Steve


----- "Alex Legler" <a3li () gentoo org> wrote:

On Sat, 12 Jun 2010 19:10:48 +0200, Alex Legler <a3li () gentoo org>
wrote:

[blah]

While we're at it...

http://www.unrealircd.com/txt/unrealsecadvisory.20090413.txt

"A buffer in the code which handles user authorization is copied
without
sufficient length checks, causing a buffer overflow.


Current thread: