Package: ngircd
Version: 0.10.0-2
Severity: important
Tags: security

Hi,

according to the ngircd homepage there's an issue in ngircd before
0.10.3:

| ngIRCd-versions previous to 0.10.3 comprise an error which can be used
| (also by remote) to crash the daemon. All installations should be
| updated to version 0.10.3 or subsequent versions.

Can you please check whether the etch version of ngircd is affected
(I'd be really surprised if not) and prepare an according update? The
diff between 0.10.2 and 0.10.3 is quite short and seems to apply.

    Christoph

-- System Information:
Debian Release: 4.0
  APT prefers stable
  APT policy: (500, 'stable')
Architecture: i386 (i686)
Shell:  /bin/sh linked to /bin/bash
Kernel: Linux 2.6.23.8
Locale: LANG=de_DE.UTF-8, LC_CTYPE=de_DE.UTF-8 (charmap=UTF-8)

Versions of packages ngircd depends on:
ii  libc6                  2.3.6.ds1-13etch2 GNU C Library: Shared libraries
ii  libssp0                4.1.1-21          GCC stack smashing protection libr

ngircd recommends no packages.

-- no debconf information

Attachment: signature.asc
Description: Digital signature

Reply via email to