KSirc: Denial of Service vulnerability KSirc is vulnerable to a Denial of Service attack. ksirc 2007-01-29 2007-01-30 159658 remote 3.5.5-r1 3.5.5-r1

KSirc is the default KDE IRC client.

KSirc fails to check the size of an incoming PRIVMSG string sent from an IRC server during the connection process.

A malicious IRC server could send a long PRIVMSG string to the KSirc client causing an assertion failure and the dereferencing of a null pointer, resulting in a crash.

There is no known workaround at this time.

All KSirc users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=kde-base/ksirc-3.5.5-r1"
CVE-2006-6811 vorlon vorlon hyakuhei