[PKG-IRC-Maintainers] Bug#572563: Bug#572563: CVE-2009-4652: Denial of service through MOTD

Christoph Biedl debian.axhn at manchmal.in-ulm.de
Thu Mar 4 22:00:30 UTC 2010


Moritz Muehlenhoff wrote...

> Please see http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4652
> for patches.

According to that page this affects only versions 13 and 14, and only
if TLS is enabled.

Currently there's 0.12.1 in Debian, and without TLS support.  You
might want to close that bug report.

> Since this package is apparently both unmaintained, unused and lagging
> behind the current upstream, the cleanest solution might be a removal
> from the archive.

I have tried to convince the maintainers to keep up with upstream for
several months now, without success.  NMU of upstream version 15 to
delayed/7 will follow within the next hours.

    Christoph





More information about the Pkg-irc-maintainers mailing list