Secunia Logo
 
Debian update for epic4
Secunia Advisory: SA10184
Release Date: 2003-11-11
Popularity: 7,069 views

Critical:
Moderately critical
Impact: DoS
System access
Where: From remote
Solution Status: Vendor Patch

OS:Debian GNU/Linux 3.0
Debian GNU/Linux unstable alias sid

Subscribe: Instant alerts on relevant vulnerabilities

CVE reference:CVE-2003-0328


Description:
Debian has issued updated packages for epic4. These fix a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a user's system.

The vulnerability is caused due to an error when handling CTCP requests from overly large nicknames (more than 512 bytes). This can be exploited by a malicious IRC server to crash a user's client and potentially execute arbitrary code on the system.

Successful exploitation requires that a user connects to a malicious IRC server.

Solution:
Apply updated packages.

-- Debian GNU/Linux 3.0 alias woody --

Source archives:

http://security.debian.org/pool/updat.../e/epic4/epic4_1.1.2.20020219-2.2.dsc
Size/MD5 checksum: 632 3bfdb704855cba1347f0d817a14ac811
http://security.debian.org/pool/updat...pic4/epic4_1.1.2.20020219-2.2.diff.gz
Size/MD5 checksum: 13465 bc712024ef53fc4f1e50e1d0a8430720
http://security.debian.org/pool/updat...pic4/epic4_1.1.2.20020219.orig.tar.gz
Size/MD5 checksum: 647989 2f5d39e7cc17fd83e455cbc442f45dd0

Alpha architecture:

http://security.debian.org/pool/updat...c4/epic4_1.1.2.20020219-2.2_alpha.deb
Size/MD5 checksum: 451484 235857ceb58e9bd9e609e4e7afac8a07

ARM architecture:

http://security.debian.org/pool/updat...pic4/epic4_1.1.2.20020219-2.2_arm.deb
Size/MD5 checksum: 374938 8c227e918cc44976951b235d2da29355

Intel IA-32 architecture:

http://security.debian.org/pool/updat...ic4/epic4_1.1.2.20020219-2.2_i386.deb
Size/MD5 checksum: 357100 9ef2ed5afc44e11b0c3d60c53e19991e

Intel IA-64 architecture:

http://security.debian.org/pool/updat...ic4/epic4_1.1.2.20020219-2.2_ia64.deb
Size/MD5 checksum: 541986 4d6c24d75acdcf326633afe0188f200d

HP Precision architecture:

http://security.debian.org/pool/updat...ic4/epic4_1.1.2.20020219-2.2_hppa.deb
Size/MD5 checksum: 423238 17447b982271b8c233a004491f76f372

Motorola 680x0 architecture:

http://security.debian.org/pool/updat...ic4/epic4_1.1.2.20020219-2.2_m68k.deb
Size/MD5 checksum: 337644 cdbc15cd7dea8abd7a407e93dded2a26

Big endian MIPS architecture:

http://security.debian.org/pool/updat...ic4/epic4_1.1.2.20020219-2.2_mips.deb
Size/MD5 checksum: 388442 53b524501e1671bd8912cf1607a50f74

Little endian MIPS architecture:

http://security.debian.org/pool/updat...4/epic4_1.1.2.20020219-2.2_mipsel.deb
Size/MD5 checksum: 389438 e8fa4bcebaab3ec6b6039d500535a1a3

PowerPC architecture:

http://security.debian.org/pool/updat.../epic4_1.1.2.20020219-2.2_powerpc.deb
Size/MD5 checksum: 384452 80bcac652557ddf726cf81b649a7c4f6

IBM S/390 architecture:

http://security.debian.org/pool/updat...ic4/epic4_1.1.2.20020219-2.2_s390.deb
Size/MD5 checksum: 370862 beb0dcb0d0fc71d6182cd12133bc58e8

Sun Sparc architecture:

http://security.debian.org/pool/updat...c4/epic4_1.1.2.20020219-2.2_sparc.deb
Size/MD5 checksum: 372884 c6db693e131441d8b6ff0147bf99625a


-- Debian GNU/Linux unstable alias sid --

Fixed in version 1.1.11.20030409-2.

Original Advisory:
http://www.debian.org/security/2003/dsa-399


Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. Sun Java JDK / JRE Multiple Vulnerabilities // 35 views
2. Microsoft XML Core Services Multiple Vulnerabilities // 28 views
3. Checkpoint VPN-1 Information Disclosure Vulnerability // 27 views
4. phpBB "url" bbcode Script Insertion Vulnerability // 26 views
5. Apple iPhone / iPod touch Multiple Vulnerabilities // 25 views
6. phpBB Avatar Script Insertion Vulnerability // 25 views
7. ArticleBeach Script "page" File Inclusion Vulnerability // 24 views
8. phpBB "gen_rand_string()" Predictable RNG Weakness // 23 views
9. phpBB reveals user IPs // 22 views
10. phpBB BBcode "url" Script Insertion Vulnerability // 21 views