Integer underflow in the clean_string function in irc_string.c in (1) IRCD-hybrid 7.2.2 and 7.2.3, (2) ircd-ratbox before 2.2.9, and (3) oftc-hybrid before 1.6.8, when flatten_links is disabled, allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a LINKS command.
CVSS Details
- CVSS 3.1 Base Score: 7.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade ircd-hybrid | Jul 30, 2024 | Feb 4, 2010 |
| Freebsd | — | Upgrade ircd-ratboxUpgrade ircd-ratbox-devel | Dec 10, 2025 | Jan 28, 2010 |
| Ubuntu | — | Upgrade ircd-hybrid | Nov 19, 2024 | Feb 4, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub