full-disclosure-uk May 2007 archive
Main Archive Page > Month Archives  > full-disclosure-uk archives
full-disclosure-uk: [Full-disclosure] [OpenPKG-SA-2007.017] Open

[Full-disclosure] [OpenPKG-SA-2007.017] OpenPKG Security Advisory (ratbox)

From: OpenPKG GmbH <openpkg-noreply_at_nospam>
Date: Fri May 18 2007 - 07:09:44 GMT
To: full-disclosure@lists.grok.org.uk


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


Publisher Name: OpenPKG GmbH Publisher Home: http://openpkg.com/ Advisory Id (public): OpenPKG-SA-2007.017 Advisory Type: OpenPKG Security Advisory (SA) Advisory Directory: http://openpkg.com/go/OpenPKG-SA Advisory Document: http://openpkg.com/go/OpenPKG-SA-2007.017 Advisory Published: 2007-05-18 09:09 UTC Issue Id (internal): OpenPKG-SI-20070518.03 Issue First Created: 2007-05-18 Issue Last Modified: 2007-05-18 Issue Revision: 02
____________________________________________________________________________
Subject Name: ratbox Subject Summary: IRC Daemon Subject Home: http://www.ircd-ratbox.org/ Subject Versions: * <= 2.2.5 Vulnerability Id: none Vulnerability Scope: global (not OpenPKG specific) Attack Feasibility: run-time Attack Vector: remote network Attack Impact: denial of service

Description:

    A Denial of Service (DoS) vulnerability exists in the Ratbox IRC     Daemon [0], versions up to and including 2.2.5. Too many pending     connections to the server from a single unknown client could result     in a resource starvation.

References:

    [0] http://www.ircd-ratbox.org/


Primary Package Name: ratbox
Primary Package Home: http://openpkg.org/go/package/ratbox

Corrected Distribution: Corrected Branch: Corrected Package: OpenPKG Enterprise E1.0-SOLID ratbox-2.2.3-E1.0.1 OpenPKG Community CURRENT ratbox-2.2.6-20070515
____________________________________________________________________________

For security reasons, this document was digitally signed with the OpenPGP public key of the OpenPKG GmbH (public key id 61B7AE34) which you can download from http://openpkg.com/openpkg.com.pgp or retrieve from the OpenPGP keyserver at hkp://pgp.openpkg.org/. Follow the instructions at http://openpkg.com/security/signatures/ for more details on how to verify the integrity of this document.


-----BEGIN PGP SIGNATURE-----
Comment: OpenPKG GmbH <http://openpkg.com/>

iD8DBQFGTVEyZwQuyWG3rjQRAoAJAKC2gBADugqr8JwcBhChaNc4uqbEOgCfQaUJ T4TUzZDzOrj3Bay0j6e5yXc=
=JOyc
-----END PGP SIGNATURE-----



Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/