CVE-2012-6084: Ircd-Ratbox

Medium severity, CVSS 5.0. EPSS: 3% chance of exploitation in the next 30 days.

modules/m_capab.c in (1) ircd-ratbox before 3.0.8 and (2) Charybdis before 3.4.2 does not properly support capability negotiation during server handshakes, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a malformed request.

Affected products

  • Ircd-Ratbox Ircd-Ratbox: version 1.0 only; version 1.1.1 only; version 1.1.2 only; version 1.2.1 only; version 1.2.2 only; version 1.2.3 only; …
  • Ratbox Ircd-Ratbox: up to and including 3.0.7

Published 2013-01-01. Last modified 2026-06-16.