Hi All!
ngIRCd 0.8.2, the "hey there are contributors" release has just hit the ground :-) Many thanks go to Florian Westphal for his work!
Everybody running an older version of ngIRCd should upgrade to this version because some remotely exploitable security related bugs (that could cause the daemon to crash) have been fixed!
Note: if you are using the CVS HEAD branch then you should run an CVS update and use the current code base.
Changes since version 0.8.1 are:
- Added doc/SSL.txt to distribution. - Fixed a buffer overflow that could cause the daemon to crash. Bug found by Florian Westphal, westphal@foo.fh-furtwangen.de. - Fixed a possible buffer underrun when reading the MOTD file. Thanks to Florian Westphal, westphal@foo.fh-furtwangen.de. - Fixed detection of IRC lines which are too long to send. Detected by Florian Westphal, westphal@foo.fh-furtwangen.de. - Fixed return values of our own implementation of strlcpy(). The code has been taken from rsync and they fixed it, but we didn't until today :-/ It has only been used when the system didn't implement strlcpy by itself, not on "modern" systems. Florian Westphal, westphal@foo.fh-furtwangen.de.
You can download ngIRCd 0.8.2 (~271 KB) from:
- http://download.berlios.de/ngircd/ngircd-0.8.2.tar.gz - ftp://ftp.berlios.de/pub/ngircd/ngircd-0.8.2.tar.gz - ftp://Arthur.Ath.CX/pub/Users/alex/ngircd/ngircd-0.8.2.tar.gz
And the patch from 0.8.1 to 0.8.2 (~3 KB) as well as GnuPG signatures can be found here:
- ftp://ftp.berlios.de/pub/ngircd/ - ftp://Arthur.Ath.CX/pub/Users/alex/ngircd/
This release has been tagged as "rel-0-8-2" in the CVS.
Regards Alex