bugs.debian.orgConfirmation
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=427157 CVE-2007-2807
Eggdrop Server Module Message Handling - Remote Buffer Overflow
Record summary
CVE-2007-2807 has a selected CVSS score of 6.8; EIP currently links 1 catalogued exploit.
Description
Stack-based buffer overflow in mod/server.mod/servrmsg.c in Eggdrop 1.6.18, and possibly earlier, allows user-assisted, remote IRC servers to execute arbitrary code via a long private message.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBEggdrop Server Module Message Handling - Remote Buffer OverflowExploitDB exploitby bangus/magnumNot analyzed1 file
References
Showing 12 of 1836237vdb entry
http://osvdb.org/36237 25276Third-party advisory
http://secunia.com/advisories/25276 26727Third-party advisory
http://secunia.com/advisories/26727 26826Third-party advisory
http://secunia.com/advisories/26826 27989Third-party advisory
http://secunia.com/advisories/27989 28347Third-party advisory
http://secunia.com/advisories/28347 35690Third-party advisory
http://secunia.com/advisories/35690 GLSA-200709-07Vendor advisory
http://security.gentoo.org/glsa/glsa-200709-07.xml 1018700vdb entry
http://securitytracker.com/id?1018700 DSA-1448Vendor advisory
http://www.debian.org/security/2008/dsa-1448 DSA-1826Vendor advisory
http://www.debian.org/security/2009/dsa-1826