CVE-2009-4016
Published Feb 4, 2010
Last updated 15 years ago
Overview
- Description
- Integer underflow in the clean_string function in irc_string.c in (1) IRCD-hybrid 7.2.2 and 7.2.3, (2) ircd-ratbox before 2.2.9, and (3) oftc-hybrid before 1.6.8, when flatten_links is disabled, allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a LINKS command.
- Source
- cve@mitre.org
- NVD status
- Analyzed
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 6.8
- Impact score
- 6.4
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-189
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:ircd-hybrid:ircd-hybrid:7.2.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "889E8F76-753E-4E71-B905-D0A481085486" }, { "criteria": "cpe:2.3:a:ircd-hybrid:ircd-hybrid:7.2.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "456247AA-A2E9-4D74-BFCC-3F7FC86A7EFF" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:ircd-ratbox:ircd-ratbox:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EF9586F6-3C0F-43E2-97D4-E683C8A52386", "versionEndIncluding": "2.2.8" }, { "criteria": "cpe:2.3:a:ircd-ratbox:ircd-ratbox:1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3F10AD4D-E56A-425F-85E2-A475913F99C1" }, { "criteria": "cpe:2.3:a:ircd-ratbox:ircd-ratbox:1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "938FDDC7-636C-4993-9EF1-805CCD6635C3" }, { "criteria": "cpe:2.3:a:ircd-ratbox:ircd-ratbox:1.1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C72A832A-3C84-4A04-9549-C4D40A1826A6" }, { "criteria": "cpe:2.3:a:ircd-ratbox:ircd-ratbox:1.1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "87E6986B-BF5A-4AB0-AF99-DDE5729B64A8" }, { "criteria": "cpe:2.3:a:ircd-ratbox:ircd-ratbox:1.2.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "830E6EFF-377A-458F-A797-09838C1105F2" }, { "criteria": "cpe:2.3:a:ircd-ratbox:ircd-ratbox:1.2.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "82F88095-0F9F-4F3A-90A2-5C694329C1B2" }, { "criteria": "cpe:2.3:a:ircd-ratbox:ircd-ratbox:1.2.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E662122C-3882-4165-AAE1-7A15A7130E19" }, { "criteria": "cpe:2.3:a:ircd-ratbox:ircd-ratbox:1.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8D58F57A-CE93-4998-8F1D-30DBD38A580F" }, { "criteria": "cpe:2.3:a:ircd-ratbox:ircd-ratbox:1.3.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "28A3F34E-F988-4CE5-BA73-7BF2318A21F8" }, { "criteria": "cpe:2.3:a:ircd-ratbox:ircd-ratbox:1.3.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EE489F4B-CA82-404E-92C4-977C30BCD8C8" }, { "criteria": "cpe:2.3:a:ircd-ratbox:ircd-ratbox:1.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AEABDAC0-B4D1-40E8-ACDF-CE9315C6B8C6" }, { "criteria": "cpe:2.3:a:ircd-ratbox:ircd-ratbox:1.4:rc1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C72372DA-913B-4588-8F18-73A8142B8971" }, { "criteria": "cpe:2.3:a:ircd-ratbox:ircd-ratbox:1.4:rc2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A6BC4E2F-D765-4800-9507-F000E02F39E2" }, { "criteria": "cpe:2.3:a:ircd-ratbox:ircd-ratbox:1.4.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AC1CFF5A-922F-4588-A068-8EA1BCFD6447" }, { "criteria": "cpe:2.3:a:ircd-ratbox:ircd-ratbox:1.4.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7F5B83AA-B724-4236-AB2E-A414F1F13BA9" }, { "criteria": "cpe:2.3:a:ircd-ratbox:ircd-ratbox:1.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "713B9BB4-C05B-4A0B-8370-5E90C04A66E2" }, { "criteria": "cpe:2.3:a:ircd-ratbox:ircd-ratbox:1.5.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0BAF6FEF-A110-4EBF-B250-6DADEB649F9E" }, { "criteria": "cpe:2.3:a:ircd-ratbox:ircd-ratbox:1.5.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4E978F29-D858-42A5-9718-8D649A48A3AA" }, { "criteria": "cpe:2.3:a:ircd-ratbox:ircd-ratbox:1.5.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C6D56D04-ADF2-4C1B-B585-70206A3430E7" }, { "criteria": "cpe:2.3:a:ircd-ratbox:ircd-ratbox:2.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1B5D2FB5-E9F6-499C-84CC-3C51CA134796" }, { "criteria": "cpe:2.3:a:ircd-ratbox:ircd-ratbox:2.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2CA73841-3490-4D5F-9A5A-20D2D966C5A3" }, { "criteria": "cpe:2.3:a:ircd-ratbox:ircd-ratbox:2.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EF5A2DE2-2321-4B0A-8B26-AC78A9099081" }, { "criteria": "cpe:2.3:a:ircd-ratbox:ircd-ratbox:2.0.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A3F16014-5F1E-426C-A426-39BCA38B49F7" }, { "criteria": "cpe:2.3:a:ircd-ratbox:ircd-ratbox:2.0.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E447E199-B731-4D97-91A0-C9D830B730A8" }, { "criteria": "cpe:2.3:a:ircd-ratbox:ircd-ratbox:2.0.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C37F551C-429B-469B-9B65-4AF571CBD03F" }, { "criteria": "cpe:2.3:a:ircd-ratbox:ircd-ratbox:2.0.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5BCA9A04-99BD-4381-9DFB-C162B015B8FE" }, { "criteria": "cpe:2.3:a:ircd-ratbox:ircd-ratbox:2.0.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "16C5CE25-71CC-4687-94B3-92D95A6CD741" }, { "criteria": "cpe:2.3:a:ircd-ratbox:ircd-ratbox:2.0.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BADFF22E-DC56-4CB7-9E9F-838FBA434FBB" }, { "criteria": "cpe:2.3:a:ircd-ratbox:ircd-ratbox:2.0.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4E2B071E-127D-441D-9E9F-DF89C06ECB94" }, { "criteria": "cpe:2.3:a:ircd-ratbox:ircd-ratbox:2.0.10:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4CBA3A86-1D7F-4A97-A8D9-9CBE3586486D" }, { "criteria": "cpe:2.3:a:ircd-ratbox:ircd-ratbox:2.0.11:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B28D5E97-4265-49FC-96AA-85380C099854" }, { "criteria": "cpe:2.3:a:ircd-ratbox:ircd-ratbox:2.1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C226114C-935E-4271-A571-85FD3E681EB8" }, { "criteria": "cpe:2.3:a:ircd-ratbox:ircd-ratbox:2.1.0:beta1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DD9E49D4-A021-4514-BF7D-95A2D3D81489" }, { "criteria": "cpe:2.3:a:ircd-ratbox:ircd-ratbox:2.1.0:beta2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2A20C33E-4F22-4A06-A913-EC78307646D4" }, { "criteria": "cpe:2.3:a:ircd-ratbox:ircd-ratbox:2.1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8C84A7D4-D72A-4375-973A-2667472DB841" }, { "criteria": "cpe:2.3:a:ircd-ratbox:ircd-ratbox:2.1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "42D63B8E-C534-4744-81D2-562A3A482D41" }, { "criteria": "cpe:2.3:a:ircd-ratbox:ircd-ratbox:2.1.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A7D5C695-2267-4796-A499-1E396588AD2A" }, { "criteria": "cpe:2.3:a:ircd-ratbox:ircd-ratbox:2.1.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "76CF693E-BDD0-444C-94DB-F1D14768334C" }, { "criteria": "cpe:2.3:a:ircd-ratbox:ircd-ratbox:2.1.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BF14F91B-1DAF-40AA-94F7-0B16E47E77A8" }, { "criteria": "cpe:2.3:a:ircd-ratbox:ircd-ratbox:2.1.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "83F77DC6-3B6C-4F7B-8BE7-0CC357F7430A" }, { "criteria": "cpe:2.3:a:ircd-ratbox:ircd-ratbox:2.1.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "20252BFB-6740-48A7-BE1E-04D5F8379D6A" }, { "criteria": "cpe:2.3:a:ircd-ratbox:ircd-ratbox:2.1.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D332723E-4015-4702-A280-BACAC965AB52" }, { "criteria": "cpe:2.3:a:ircd-ratbox:ircd-ratbox:2.2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "656BE9FD-6B12-4341-B431-292FA7ADFA85" }, { "criteria": "cpe:2.3:a:ircd-ratbox:ircd-ratbox:2.2.0:rc1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "25F7ACAE-DCA7-4129-8FFE-34D99B9E5E92" }, { "criteria": "cpe:2.3:a:ircd-ratbox:ircd-ratbox:2.2.0:rc2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1071515E-4989-4930-8B3E-871056E15C38" }, { "criteria": "cpe:2.3:a:ircd-ratbox:ircd-ratbox:2.2.0:rc3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "10DFD9BC-51AB-4D29-87FB-E253E9B9DF78" }, { "criteria": "cpe:2.3:a:ircd-ratbox:ircd-ratbox:2.2.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FD99110C-908D-44D5-9E1B-76A3F69853B6" }, { "criteria": "cpe:2.3:a:ircd-ratbox:ircd-ratbox:2.2.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5DF583AA-01F9-4BFD-9B0E-037446EC0C49" }, { "criteria": "cpe:2.3:a:ircd-ratbox:ircd-ratbox:2.2.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5C08834C-326C-4FDD-94F6-BE7802365120" }, { "criteria": "cpe:2.3:a:ircd-ratbox:ircd-ratbox:2.2.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "726E772C-EC4E-48C7-A0DC-A7F715611425" }, { "criteria": "cpe:2.3:a:ircd-ratbox:ircd-ratbox:2.2.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BCF7D8EB-E5E4-4EBC-851F-DEB78123A562" }, { "criteria": "cpe:2.3:a:ircd-ratbox:ircd-ratbox:2.2.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0DC87A6A-A2BF-4ED4-8987-E2B097223325" }, { "criteria": "cpe:2.3:a:ircd-ratbox:ircd-ratbox:2.2.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "12F18235-5596-44B7-A5AE-5D2F71011C39" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:oftc:oftc-hybrid:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F0C7CC91-D13E-4542-9A23-32A6BAE9E810", "versionEndIncluding": "1.6.7" }, { "criteria": "cpe:2.3:a:oftc:oftc-hybrid:1.4.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "ADFC3894-A09E-4F10-8418-50176A3A7F45" }, { "criteria": "cpe:2.3:a:oftc:oftc-hybrid:1.4.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D457B8CD-99B0-4E11-B68C-39BA84E58906" }, { "criteria": "cpe:2.3:a:oftc:oftc-hybrid:1.5.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E6ECF9A5-0470-4C62-9003-3899E19C33B4" }, { "criteria": "cpe:2.3:a:oftc:oftc-hybrid:1.5.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0652A5D0-144C-4433-9994-C492F529FCD5" }, { "criteria": "cpe:2.3:a:oftc:oftc-hybrid:1.5.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0889D77B-03B4-43AA-8EE3-281ACC5E6EEB" }, { "criteria": "cpe:2.3:a:oftc:oftc-hybrid:1.5.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8D241E0E-0D80-48CC-8ED5-0339B627C514" }, { "criteria": "cpe:2.3:a:oftc:oftc-hybrid:1.5.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E0A5715B-9A87-492C-88DE-D4FD8790BD0B" }, { "criteria": "cpe:2.3:a:oftc:oftc-hybrid:1.5.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8BBD5C78-0EA5-448F-84E3-8EB5AC565576" }, { "criteria": "cpe:2.3:a:oftc:oftc-hybrid:1.5.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "37FDF780-1A2B-4F94-AB56-B550621534B6" }, { "criteria": "cpe:2.3:a:oftc:oftc-hybrid:1.5.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BAA0465A-3FE6-421D-9BA4-BE7B33CBFD83" }, { "criteria": "cpe:2.3:a:oftc:oftc-hybrid:1.6.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AB1B5E26-3140-428E-BBFB-061AA91FC640" }, { "criteria": "cpe:2.3:a:oftc:oftc-hybrid:1.6.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9F1537A5-EF6A-4B27-A15E-6DE1369BC4AE" }, { "criteria": "cpe:2.3:a:oftc:oftc-hybrid:1.6.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "21D5234E-7A16-42CA-9DE0-A46A44EE9C5C" }, { "criteria": "cpe:2.3:a:oftc:oftc-hybrid:1.6.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6E0ED787-EA64-4022-963D-44A27FEE2B91" }, { "criteria": "cpe:2.3:a:oftc:oftc-hybrid:1.6.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1D714B5C-12F2-4A88-9F4D-5B173C5BFB23" }, { "criteria": "cpe:2.3:a:oftc:oftc-hybrid:1.6.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2A3B8A7C-E6C5-459E-A097-C5C5EF830F46" }, { "criteria": "cpe:2.3:a:oftc:oftc-hybrid:1.6.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "009344FF-0CE8-4067-A90B-661047D94629" } ], "operator": "OR" } ] } ]