ngIRCd: Denial of service — GLSA 200801-13 ngIRCd does not properly sanitize commands sent by users, allowing for a Denial of Service. Affected packages Package net-irc/ngircd on all architectures Affected versions < 0.10.4 Unaffected versions >= 0.10.4 Background ngIRCd is a free open source daemon for Internet Relay Chat (IRC). Description The IRC_PART() function in the file irc-channel.c does not properly check the number of parameters, referencing an invalid pointer if no channel is supplied. Impact A remote attacker can exploit this vulnerability to crash the ngIRCd daemon. Workaround There is no known workaround at this time. Resolution All ngIRCd users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=net-irc/ngircd-0.10.4" References CVE-2008-0285