CVE-2013-5580: Barton Ngircd
Medium severity, CVSS 4.3. EPSS: 2.3% chance of exploitation in the next 30 days.
The (1) Conn_StartLogin and (2) cb_Read_Resolver_Result functions in conn.c in ngIRCd 18 through 20.2, when the configuration option NoticeAuth is enabled, does not properly handle the return code for the Handle_Write function, which allows remote attackers to cause a denial of service (assertion failure and server crash) via unspecified vectors, related to a "notice auth" message not being sent to a new client.
Affected products
- Barton Ngircd: version 18.0 only; version 19.0 only; version 19.1 only; version 20.0 only; version 20.1 only; version 20.2 only
Published 2013-10-01. Last modified 2026-06-16.