Security 10748 Published by

Updated EPIC packages which fix an exploitable buffer overflow vulnerabilityare now available.



EPIC (Enhanced Programmable ircII Client) is an advanced ircII chat client designed to connect to Internet Relay Chat (IRC) servers. A bug in various versions of EPIC allows remote malicious IRC servers tocause a denial of service (crash) and execute arbitrary code via a CTC Prequest from a large nickname, which causes an incorrect lengthcalculation. The Common Vulnerabilities and Exposures project(cve.mitre.org) has assigned the name CAN-2003-0328 to this issue.Users of EPIC who may connect to untrusted servers are advised to upgrade to the packages in this erratum which contain a backported security fix tocorrect this issue.
Read more