Vulnerabilities > CVE-2009-4016 - Numeric Errors vulnerability in multiple products

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL

Summary

Integer underflow in the clean_string function in irc_string.c in (1) IRCD-hybrid 7.2.2 and 7.2.3, (2) ircd-ratbox before 2.2.9, and (3) oftc-hybrid before 1.6.8, when flatten_links is disabled, allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a LINKS command.

Vulnerable Configurations

Part Description Count
Application
Ircd-Hybrid
2
Application
Ircd-Ratbox
54
Application
Oftc
18

Common Weakness Enumeration (CWE)

Nessus

  • NASL familyDebian Local Security Checks
    NASL idDEBIAN_DSA-1980.NASL
    descriptionDavid Leadbeater discovered an integer underflow that could be triggered via the LINKS command and can lead to a denial of service or the execution of arbitrary code (CVE-2009-4016 ). This issue affects both, ircd-hybrid and ircd-ratbox. It was discovered that the ratbox IRC server is prone to a denial of service attack via the HELP command. The ircd-hybrid package is not vulnerable to this issue (CVE-2010-0300 ).
    last seen2020-06-01
    modified2020-06-02
    plugin id44844
    published2010-02-24
    reporterThis script is Copyright (C) 2010-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/44844
    titleDebian DSA-1980-1 : ircd-hybrid/ircd-ratbox - integer underflow/denial of service
  • NASL familyFreeBSD Local Security Checks
    NASL idFREEBSD_PKG_192609C80C5111DF82A000248C9B4BE7.NASL
    descriptionSecurityFocus reports : The first affects the /quote HELP module and allows a user to trigger an IRCD crash on some platforms. The second affects the /links processing module when the flatten_links configuration option is not enabled.
    last seen2020-06-01
    modified2020-06-02
    plugin id44333
    published2010-01-29
    reporterThis script is Copyright (C) 2010-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/44333
    titleFreeBSD : irc-ratbox -- multiple vulnerabilities (192609c8-0c51-11df-82a0-00248c9b4be7)
  • NASL familyFedora Local Security Checks
    NASL idFEDORA_2010-9312.NASL
    descriptionTwo vulnerabilities were reported in ircd-hybrid, ircd-ratbox, and oftc-hybrid. The first is an integer overflow that can lead to a denial of service or, possibly, the execution of arbitrary code on the ircd server (CVE-2009-4016 (patch [1])), the second is a NULL pointer dereference that can lead to a denial of service of the ircd server (CVE-2010-0300 (patch [2])). This has been corrected in upstream ircd-ratbox 2.2.9 [3]. CVE-2010-0300 may be ircd- ratbox specific, however CVE-2009-4016 affects both ircd servers. [1] http://ircd.ratbox.org/cgi-bin/index.cgi/ircd- ratbox/branches/RATBOX_3_0/src/cache.c?r1=26334&r2=26732 [2] http://trac.oftc.net/projects/oftc-hybrid/changeset/1062 [3] http://lists.ratbox.org/pipermail/ircd-ratbox/2010-January/000891.html Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-06-01
    modified2020-06-02
    plugin id47529
    published2010-07-01
    reporterThis script is Copyright (C) 2010-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/47529
    titleFedora 12 : ircd-hybrid-7.2.3-11.fc12 / ircd-ratbox-2.2.8-7.fc12 (2010-9312)