Quantcast
Channel: BOT24
Viewing all articles
Browse latest Browse all 8064

ircd-hybrid: Denial of service vulnerability in hostmask.c:try_parse_v4_netmask()

$
0
0

Mr. Bob Nomnomnom from Torland reported a denial of service security
vulnerability in ircd-hybrid. Function hostmask.c:try_parse_v4_netmask() is
using strtoul to parse masks. Documentation says strtoul can parse "-number" as
well.


Fixed in commit: 
http://svn.ircd-hybrid.org:8000/viewcvs.cgi/ircd-hybrid/trunk/src/hostmask.c?r1=1786&r2=1785&pathrev=1786
Fixed in: ircd-hybrid 8.0.6
--
Henri Salo
henri@nerv.fi





//The information contained within this publication is
//supplied "as-is"with no warranties or guarantees of fitness
//of use or otherwise. Bot24, Inc nor Bradley Sean Susser accepts
//responsibility for any damage caused by the use or misuse of
//this information





Viewing all articles
Browse latest Browse all 8064

Trending Articles