EnergyMech: Denial of Service A Denial of Service vulnerability was discovered in EnergyMech that is easily exploitable via IRC. emech June 26, 2006 July 29, 2006: 02 132749 remote 3.0.2 3.0.2

EnergyMech is an IRC bot programmed in C.

A bug in EnergyMech fails to handle empty CTCP NOTICEs correctly, and will cause a crash from a segmentation fault.

By sending an empty CTCP NOTICE, a remote attacker could exploit this vulnerability to cause a Denial of Service.

There is no known workaround at this time.

All EnergyMech users should update to the latest stable version:

# emerge --sync # emerge --ask --oneshot --verbose ">=net-irc/emech-3.0.2"
EnergyMech Changelog CVE-2006-3293 jaervosz hlieberman falco