Description: Debian has issued updated packages for epic4. These fix a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a user's system.
The vulnerability is caused due to an error when handling CTCP requests from overly large nicknames (more than 512 bytes). This can be exploited by a malicious IRC server to crash a user's client and potentially execute arbitrary code on the system.
Successful exploitation requires that a user connects to a malicious IRC server.
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.