From bfa25459fcfaf5bcb4803ff598d72208fd920580 Mon Sep 17 00:00:00 2001 From: Kevin Bowling Date: Tue, 15 Jun 2021 08:46:39 -0700 Subject: security/vuxml: Document CVE-2021-29376 for irc/ircII PR: 255492 Reported by: Andrew Gierth --- security/vuxml/vuln.xml | 27 +++++++++++++++++++++++++++ 1 file changed, 27 insertions(+) diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index 3766ec508c13..b6888cba5bb4 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -76,6 +76,33 @@ Notes: * Do not forget port variants (linux-f10-libxml2, libxml2, etc.) --> + + ircII -- denial of service + + + ircii + 20210314 + + + + +

Michael Ortmann reports:

+
+

ircii has a bug in parsing CTCP UTC messages.

+

Its unknown if this could also be used for arbitrary code execution.

+
+ +
+ + CVE-2021-29376 + https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-29376 + + + 2021-03-02 + 2021-03-30 + +
+ Apache httpd -- Multiple vulnerabilities -- cgit v1.2.3