vendor:
ircd-hybrid
by:
kingcope
7,5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: ircd-hybrid
Affected Version From: 8.0.5
Affected Version To: 8.0.5
Patch Exists: YES
Related CWE: CVE-2013-0238
CPE: a:ircd-hybrid:ircd-hybrid:8.0.5
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: CentOS 6
2013
ircd-hybrid remote denial of service exploit for CVE-2013-0238
This exploit is a quick and dirty h4x by kingcope for ircd-hybrid-8.0.5 centos6. It uses Socket to connect to the server and sends a malicious MODE command with a negative number as a parameter to crash the server.
Mitigation:
Upgrade to the latest version of ircd-hybrid and apply the patch for CVE-2013-0238.