|
|
Info |
Last Modified |
| 7 months ago |
|
|
|
|
Description |
UnrealIRCd contains a flaw that may lead to an unauthorized IP information disclosure. The issue is due to the weakIP cloaking algorithm, which is intended to prevent IP bruteforce. By knowning one plaintext and hashed IP address and another hashed IP address, a remote attacker can recover the keys of several IRC networks and get the IP addresses, resulting in a loss of confidentiality.
|
|
Classification |
Location:
Remote/Network Access Required
Attack Type:
Cryptographic,
Information Disclosure
Impact:
Loss of Confidentiality
Exploit:
Exploit Available
Disclosure:
OSVDB Verified
|
|
Solution |
Upgrade to version 3.2.1 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.
|
|
Products |
|
Unrealircd
 |
3.2 |
|
|
|
|
|
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|