GLSA-200606-26 : EnergyMech: Denial of Service
Medium Nessus Plugin ID 21759
SynopsisThe remote Gentoo host is missing one or more security-related patches.
DescriptionThe remote host is affected by the vulnerability described in GLSA-200606-26 (EnergyMech: Denial of Service)
A bug in EnergyMech fails to handle empty CTCP NOTICEs correctly, and will cause a crash from a segmentation fault.
By sending an empty CTCP NOTICE, a remote attacker could exploit this vulnerability to cause a Denial of Service.
There is no known workaround at this time.
SolutionAll EnergyMech users should update to the latest stable version:
# emerge --sync # emerge --ask --oneshot --verbose '>=net-irc/emech-3.0.2'