Bug#487867: tirc: crash [SEGV] when server sends numeric replies =600 (e.g. freenode's hyperion with nickserv)

2008-07-30 Thread Teemu Hukkanen
Thijs Kinkhorst [EMAIL PROTECTED] writes: This package should probably be removed from the archive, as it is dead upstream and likely to be riddled with security bugs if this is any indicator. Unfortunately it is in stable already. For starters we can at least reduce the burden by

Bug#487867: tirc: crash [SEGV] when server sends numeric replies =600 (e.g. freenode's hyperion with nickserv)

2008-07-29 Thread Thijs Kinkhorst
Hi Ben, On Tuesday 29 July 2008 02:45, Ben Hutchings wrote: This bug is rather likely to be exploitable for executing arbitrary code. There also appear to be a bunch of places where buffer overflows are possible. Thanks for letting us know. I must say that reading that it crashes on very

Bug#487867: tirc: crash [SEGV] when server sends numeric replies =600 (e.g. freenode's hyperion with nickserv)

2008-07-28 Thread Ben Hutchings
This bug is rather likely to be exploitable for executing arbitrary code. There also appear to be a bunch of places where buffer overflows are possible. This package should probably be removed from the archive, as it is dead upstream and likely to be riddled with security bugs if this is any

Bug#487867: tirc: crash [SEGV] when server sends numeric replies =600 (e.g. freenode's hyperion with nickserv)

2008-06-24 Thread Bernhard Reiter
Package: tirc Version: 1.2-11 Severity: grave Justification: renders package unusable Go to irc.freeonode.net and identify yourself with /msg nickserv, the response will be with numeric reply 901 and makes tirc crash with a segmentation fault. (tirc -d shows the server response.) This will