CVE-2009-4016

UnknownEPSS 4.03%

Last modified

CVE-2009-4016 is a vulnerability of currently unknown severity. Integer underflow in the clean_string function in irc_string.c in (1) IRCD-hybrid 7.2.2 and 7.2.3, (2) ircd-ratbox before 2.2.9, and (3) oftc-hybrid before 1.6.8, when flatten_links is disabled, allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a LINKS command.. EPSS estimates a 4.03% chance of exploitation in the next 30 days.

Description

Integer underflow in the clean_string function in irc_string.c in (1) IRCD-hybrid 7.2.2 and 7.2.3, (2) ircd-ratbox before 2.2.9, and (3) oftc-hybrid before 1.6.8, when flatten_links is disabled, allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a LINKS command.

Metrics

EPSS Probability
4.03%

89.3th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
Ircd-HybridIrcd-Hybrid7.2.2
Ircd-HybridIrcd-Hybrid7.2.3
Ircd-RatboxIrcd-Ratbox<= 2.2.8
Ircd-RatboxIrcd-Ratbox1.0
Ircd-RatboxIrcd-Ratbox1.1
Ircd-RatboxIrcd-Ratbox1.1.1
Ircd-RatboxIrcd-Ratbox1.1.2
Ircd-RatboxIrcd-Ratbox1.2.1
Ircd-RatboxIrcd-Ratbox1.2.2
Ircd-RatboxIrcd-Ratbox1.2.3
Ircd-RatboxIrcd-Ratbox1.3
Ircd-RatboxIrcd-Ratbox1.3.1
Ircd-RatboxIrcd-Ratbox1.3.2
Ircd-RatboxIrcd-Ratbox1.4
Ircd-RatboxIrcd-Ratbox1.4.1
Ircd-RatboxIrcd-Ratbox1.4.2
Ircd-RatboxIrcd-Ratbox1.5
Ircd-RatboxIrcd-Ratbox1.5.1
Ircd-RatboxIrcd-Ratbox1.5.2
Ircd-RatboxIrcd-Ratbox1.5.3
Ircd-RatboxIrcd-Ratbox2.0.0
Ircd-RatboxIrcd-Ratbox2.0.1
Ircd-RatboxIrcd-Ratbox2.0.2
Ircd-RatboxIrcd-Ratbox2.0.3
Ircd-RatboxIrcd-Ratbox2.0.4
Ircd-RatboxIrcd-Ratbox2.0.5
Ircd-RatboxIrcd-Ratbox2.0.6
Ircd-RatboxIrcd-Ratbox2.0.7
Ircd-RatboxIrcd-Ratbox2.0.8
Ircd-RatboxIrcd-Ratbox2.0.9
Ircd-RatboxIrcd-Ratbox2.0.10
Ircd-RatboxIrcd-Ratbox2.0.11
Ircd-RatboxIrcd-Ratbox2.1.0
Ircd-RatboxIrcd-Ratbox2.1.1
Ircd-RatboxIrcd-Ratbox2.1.2
Ircd-RatboxIrcd-Ratbox2.1.3
Ircd-RatboxIrcd-Ratbox2.1.4
Ircd-RatboxIrcd-Ratbox2.1.5
Ircd-RatboxIrcd-Ratbox2.1.6
Ircd-RatboxIrcd-Ratbox2.1.7
Ircd-RatboxIrcd-Ratbox2.1.8
Ircd-RatboxIrcd-Ratbox2.2.0
Ircd-RatboxIrcd-Ratbox2.2.1
Ircd-RatboxIrcd-Ratbox2.2.2
Ircd-RatboxIrcd-Ratbox2.2.3
Ircd-RatboxIrcd-Ratbox2.2.4
Ircd-RatboxIrcd-Ratbox2.2.5
Ircd-RatboxIrcd-Ratbox2.2.6
Ircd-RatboxIrcd-Ratbox2.2.7
OftcOftc-Hybrid<= 1.6.7

Showing 50 of 67 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2009-4016?
Integer underflow in the clean_string function in irc_string.c in (1) IRCD-hybrid 7.2.2 and 7.2.3, (2) ircd-ratbox before 2.2.9, and (3) oftc-hybrid before 1.6.8, when flatten_links is disabled, allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a LINKS command.
How severe is CVE-2009-4016?
Severity scoring for CVE-2009-4016 is pending analysis. The EPSS model estimates a 4.03% probability of exploitation in the next 30 days.
How do I fix CVE-2009-4016?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2009-4016?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST