EnergyMech: Denial of service A Denial of Service vulnerability was discovered in EnergyMech that is easily exploitable via IRC. emech 2006-06-26 2006-07-29 132749 remote 3.0.2 3.0.2

EnergyMech is an IRC bot programmed in C.

A bug in EnergyMech fails to handle empty CTCP NOTICEs correctly, and will cause a crash from a segmentation fault.

By sending an empty CTCP NOTICE, a remote attacker could exploit this vulnerability to cause a Denial of Service.

There is no known workaround at this time.

All EnergyMech users should update to the latest stable version:

# emerge --sync # emerge --ask --oneshot --verbose ">=net-irc/emech-3.0.2"
EnergyMech Changelog CVE-2006-3293 jaervosz hlieberman falco