Description: Debian has issued updated packages for epic4. These fix a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a user's system.
The vulnerability is caused due to an error when handling CTCP requests from overly large nicknames (more than 512 bytes). This can be exploited by a malicious IRC server to crash a user's client and potentially execute arbitrary code on the system.
Successful exploitation requires that a user connects to a malicious IRC server.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.