--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2009-5568
2009-05-28 07:01:45
--------------------------------------------------------------------------------

Name        : eggdrop
Product     : Fedora 9
Version     : 1.6.19
Release     : 4.fc9
URL         : http://www.eggheads.org/
Summary     : The world's most popular Open Source IRC bot
Description :
Eggdrop is the world's most popular Open Source IRC bot, designed
for flexibility and ease of use. It is extendable with Tcl scripts
and/or C modules, has support for the big five IRC networks and is
able to form botnets, share partylines and userfiles between bots.

--------------------------------------------------------------------------------
Update Information:

mod/server.mod/servmsg.c in Eggheads Eggdrop and Windrop 1.6.19 and earlier
allows remote attackers to cause a denial of service (crash) via a crafted
PRIVMSG that causes an empty string to trigger a negative string length copy.
NOTE: this issue exists because of an incorrect fix for CVE-2007-2807. The
current remote denial of service is tracked as CVE-2009-1789.
--------------------------------------------------------------------------------
ChangeLog:

* Tue May 26 2009 Robert Scheck  1.6.19-4
- Added upstream ctcpfix to solve CVE-2009-1789 (#502650)
* Mon Feb 23 2009 Robert Scheck  1.6.19-3
- Rebuild for gcc 4.4 and rpm 4.6
* Sat Aug 30 2008 Robert Scheck  1.6.19-2
- Re-diffed eggdrop configuration patch for no fuzz
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #502650 - CVE-2009-1789 eggdrop DoS (crash)
        https://bugzilla.redhat.com/show_bug.cgi?id=502650
--------------------------------------------------------------------------------

This update can be installed with the "yum" update program.  Use 
su -c 'yum update eggdrop' at the command line.
For more information, refer to "Managing Software with yum",
available at .

All packages are signed with the Fedora Project GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/security/
--------------------------------------------------------------------------------

_______________________________________________
Fedora-package-announce mailing list
Fedora-package-announce@redhat.com
http://www.redhat.com/mailman/listinfo/fedora-package-announce

Fedora 9 Update: eggdrop-1.6.19-4.fc9

May 28, 2009
mod/server.mod/servmsg.c in Eggheads Eggdrop and Windrop 1.6.19 and earlier allows remote attackers to cause a denial of service (crash) via a crafted PRIVMSG that causes an empty...

Summary

Eggdrop is the world's most popular Open Source IRC bot, designed

for flexibility and ease of use. It is extendable with Tcl scripts

and/or C modules, has support for the big five IRC networks and is

able to form botnets, share partylines and userfiles between bots.

Update Information:

mod/server.mod/servmsg.c in Eggheads Eggdrop and Windrop 1.6.19 and earlier allows remote attackers to cause a denial of service (crash) via a crafted PRIVMSG that causes an empty string to trigger a negative string length copy. NOTE: this issue exists because of an incorrect fix for CVE-2007-2807. The current remote denial of service is tracked as CVE-2009-1789.

Change Log

* Tue May 26 2009 Robert Scheck 1.6.19-4 - Added upstream ctcpfix to solve CVE-2009-1789 (#502650) * Mon Feb 23 2009 Robert Scheck 1.6.19-3 - Rebuild for gcc 4.4 and rpm 4.6 * Sat Aug 30 2008 Robert Scheck 1.6.19-2 - Re-diffed eggdrop configuration patch for no fuzz

References

[ 1 ] Bug #502650 - CVE-2009-1789 eggdrop DoS (crash) https://bugzilla.redhat.com/show_bug.cgi?id=502650

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update eggdrop' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
Name : eggdrop
Product : Fedora 9
Version : 1.6.19
Release : 4.fc9
URL : http://www.eggheads.org/
Summary : The world's most popular Open Source IRC bot

Related News