Open Projects Network Internet Relay Chat (IRC) daemon u2.10.05.18 does not perform a double-reverse DNS lookup, which allows remote attackers to spoof any valid hostname on the Internet. NOTE: a followup post suggests that this is not an issue in the daemon.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/220380 | mailing list |
http://www.securityfocus.com/archive/1/219388/2003-04-27/2003-05-03/2 | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/7283 | vdb entry |