|
IRCD-Hybrid and ircd-ratbox contain a flaw that may allow a remote denial of service. The issue is due to no rate limit imposed in the "parse_client_queued" function when an unidentified client sends lines. By establishing an unregistered connection and sending multiple newlines, a remote attacker can exhaust large amounts of memory resources and will result in loss of availability for the platform.
|