Possible DoS Found in IRCd-Ratbox

A possible DoS has been found in IRCd-Ratbox. This IRCd is in use on EFNet and other smaller networks.

The discovery was announced on the Ratbox mailinglist by Lee H: “We have recently uncovered a potential DoS in ircd-ratbox that could result in resource starvation of the CPU.”

The bug dates back to very early version of Ratbox, which makes it a vulnerability that is presence in all flavors of the IRCd in use.

“We have now released ircd-ratbox-2.2.6, it is recommended that everybody upgrades — the attack is fairly easy to abuse.  Details follow in the next email”, Lee ends. Since then, Lee retracted to give more details about the exploit to prevent malicious users causing havoc.

Thanks to Kobi for the tip.

Related posts:

  1. New ircd-ratbox stable release fixes crashbugs [Updated] Developer androsyn just announced the availability of ircd-ratbox 2.2.9, a...
  2. ircd-ratbox releases version 3.0.5 ircd-ratbox, the “advanced, stable and fast ircd” which is “the...
  3. ratbox-services version 1.2.2 released ratbox-services, a services package for use with IRCd-ratbox is now...
  4. ircd-ratbox 3.0.1 released Yesterday, the ircd-ratbox project announced the release of their latest...
  5. ratbox-services release version 1.2.3 ratbox-services, a services package for use with IRCd-ratbox is now...

Tags: , ,

Leave a Reply