I would just like to point out this is ONLY applied to debian. InspIRCd itself has fixed this 3 years ago, and until now debian refused to fix this in their repo.
On Wed, Apr 15, 2015 at 10:42 AM, Sebastien Delafond <[email protected]> wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA256 > > - ------------------------------------------------------------------------- > Debian Security Advisory DSA-3226-1 [email protected] > http://www.debian.org/security/ Sebastien Delafond > April 15, 2015 http://www.debian.org/security/faq > - ------------------------------------------------------------------------- > > Package : inspircd > Debian Bug : 780880 > > [email protected] discovered several problems in inspircd, an IRC daemon: > > - an incomplete patch for CVE-2012-1836 failed to adequately resolve > the problem where maliciously crafted DNS requests could lead to > remote code execution through a heap-based buffer overflow. > > - the incorrect processing of specific DNS packets could trigger an > infinite loop, thus resulting in a denial of service. > > For the stable distribution (wheezy), this problem has been fixed in > version 2.0.5-1+deb7u1. > > For the upcoming stable distribution (jessie) and unstable > distribution (sid), this problem has been fixed in version 2.0.16-1. > > We recommend that you upgrade your inspircd packages. > > Further information about Debian Security Advisories, how to apply > these updates to your system and frequently asked questions can be > found at: https://www.debian.org/security/ > > Mailing list: [email protected] > -----BEGIN PGP SIGNATURE----- > Version: GnuPG v2 > > iQEcBAEBCAAGBQJVLoRHAAoJEBC+iYPz1Z1kO6wIAL9ONDnBUaddsmnW8wMvBScS > G9Lx4gnP6+3zh9MS3h+c71udMwjqDntoHmZ214Dlc8dDT2o2XDb1ATxbtkdW5oNA > UYTJgrBlwWFeeR5p7tliIwEZVviUULb52RIQUUNzEd/vKgXuOvluIBYPnln2wulw > o81qAVs+ObUqohEFk7H2/SSkgbPNkqjmdgpVIDGmQNoXOWzKV65q7RBWXqLRYb4B > 2ujGpt9YEtlzw2Elnkeb7ygwZWDnXcLwOX3r6EITWEJXBhNA0Z4tCcBL/N6tIbZf > xjJt5yey+QudxHr8GfOfk9Fccicueh7fSgPRqGvS23BF8tGVd4Bo9ijsiz0tqUA= > =G6c1 > -----END PGP SIGNATURE----- > > > -- > To UNSUBSCRIBE, email to [email protected] > with a subject of "unsubscribe". Trouble? Contact > [email protected] > Archive: https://lists.debian.org/[email protected] > >

