Lucene search

K
cve[email protected]CVE-2009-1789
HistoryMay 26, 2009 - 4:30 p.m.

CVE-2009-1789

2009-05-2616:30:02
web.nvd.nist.gov
24
cve-2009-1789
information security
denial of service
eggheads eggdrop
windrop
remote attack

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

6.3 Medium

AI Score

Confidence

Low

0.049 Low

EPSS

Percentile

92.8%

mod/server.mod/servmsg.c in Eggheads Eggdrop and Windrop 1.6.19 and earlier allows remote attackers to cause a denial of service (crash) via a crafted PRIVMSG that causes an empty string to trigger a negative string length copy. NOTE: this issue exists because of an incorrect fix for CVE-2007-2807.

Affected configurations

NVD
Node
eggheadseggdropMatch1.6.0
OR
eggheadseggdropMatch1.6.1
OR
eggheadseggdropMatch1.6.2
OR
eggheadseggdropMatch1.6.3
OR
eggheadseggdropMatch1.6.4
OR
eggheadseggdropMatch1.6.5
OR
eggheadseggdropMatch1.6.6
OR
eggheadseggdropMatch1.6.7
OR
eggheadseggdropMatch1.6.8
OR
eggheadseggdropMatch1.6.9
OR
eggheadseggdropMatch1.6.10
OR
eggheadseggdropMatch1.6.11
OR
eggheadseggdropMatch1.6.12
OR
eggheadseggdropMatch1.6.13
OR
eggheadseggdropMatch1.6.14
OR
eggheadseggdropMatch1.6.15
OR
eggheadseggdropMatch1.6.16
OR
eggheadseggdropMatch1.6.17
OR
eggheadseggdropMatch1.6.18
OR
eggheadseggdropMatch1.6.18rc1
OR
eggheadseggdrop_irc_botRange≀1.6.19
OR
philip_moorewindropRange≀1.6.19
OR
philip_moorewindropMatch1.4.4final
OR
philip_moorewindropMatch1.4.6
OR
philip_moorewindropMatch1.5.4final
OR
philip_moorewindropMatch1.5.4rc1
OR
philip_moorewindropMatch1.5.4rc2
OR
philip_moorewindropMatch1.5.4a
OR
philip_moorewindropMatch1.6.0final
OR
philip_moorewindropMatch1.6.0rc1
OR
philip_moorewindropMatch1.6.0rc1-rel2
OR
philip_moorewindropMatch1.6.1
OR
philip_moorewindropMatch1.6.2\+bindsfix
OR
philip_moorewindropMatch1.6.3
OR
philip_moorewindropMatch1.6.4sr1
OR
philip_moorewindropMatch1.6.6
OR
philip_moorewindropMatch1.6.7
OR
philip_moorewindropMatch1.6.8
OR
philip_moorewindropMatch1.6.9
OR
philip_moorewindropMatch1.6.10
OR
philip_moorewindropMatch1.6.12
OR
philip_moorewindropMatch1.6.13
OR
philip_moorewindropMatch1.6.15
OR
philip_moorewindropMatch1.6.16
OR
philip_moorewindropMatch1.6.17
OR
philip_moorewindropMatch1.6.18
OR
philip_moorewindropMatch1.6.19\+ctcpfix

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

6.3 Medium

AI Score

Confidence

Low

0.049 Low

EPSS

Percentile

92.8%